Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Research has revealed that decade-old Microsoft-signed UEFI shims can be used to bypass Secure Boot protections.
Answered
Who discovered the vulnerability?
The vulnerability was discovered by ESET Research.
What specifically allows the Secure Boot bypass?
Old Microsoft-signed UEFI shims, specifically 11 Linux UEFI shims, can be used to bypass the system.
How long has this issue existed?
According to coverage from Ars Technica, the system has been broken for a decade.
🌍 Cross-language spread
Newsylist detected this story across 2 language editions of the world's news.
Detected by matching proper nouns and figures that survive translation. Times reflect when each edition's coverage was first indexed.
Where it stands
ESET Research has discovered that vulnerable UEFI shims are undermining the Secure Boot process on devices. These old, Microsoft-signed applications allow attackers to bypass the security measures intended to protect the boot process.
Coverage from Ars Technica, The Hacker News, and SC Media emphasizes that 11 of these old Linux UEFI shims are specifically problematic. WeLiveSecurity and The Manila Times highlight that these forgotten shims have remained a vulnerability for a decade without being noticed.
Future developments depend on how these specific Microsoft-signed UEFI applications are addressed to prevent attackers from bypassing Secure Boot.
Synthesized by Newsylist from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 45d ago.
Coverage (9)
- Forgotten Microsoft-Signed Bootloaders Let Hackers Bypass Secure Boot For 11 Years HotHardware · 45d ago
- Windows 11 KB5101650, KB5094126 fixes major flaw that went unnoticed for over 10 years Neowin · 45d ago
- Microsoft finally patched Secure Boot bypasses that were hiding in plain sight since 2013 TechSpot · 45d ago
- Microsoft’s Secure Boot has been broken for a decade and no one noticed until now Ars Technica · 45d ago broke it first
- ESET Research discovers vulnerable UEFI shims undermining devices’ Secure Boot The Manila Times · 45d ago
- Old Microsoft-signed UEFI applications can bypass Secure Boot SC Media · 45d ago
- 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot The Hacker News · 45d ago
- Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 45d ago
- Microsoft’s Secure Boot has been broken for a decade and no one noticed until now Ars Technica · 45d ago broke it first
The coverage curve
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
People, places & organizations
Topics
Related trends
Ikea’s Xbox collection includes a giant thumbstick stool
IKEA and Xbox launch a gaming‑themed furniture line, turning the controller’s thumbstick into a giant stool.
Microsoft is combining its Copilot apps ahead of a ‘super app’
Microsoft is merging consumer and business Copilot tools into a single platform ahead of a planned super app.
Microsoft is rolling out big Windows 11 improvements in August and here’s everything you should know
Microsoft prepares a major Windows 11 update for August featuring accessibility enhancements and critical fixes following recent system outages.
Amazon, Meta and Microsoft face skeptical investors this week after Google report sparked sell-off
A Google AI spending report fuels investor skepticism across Amazon, Meta and Microsoft, sparking a market sell‑off.
Update: Xbox Online Services Fully Restored After Hours-Long Outage
Xbox online services have resumed following a 16-hour disruption that blocked game access and fueled debates over all-digital media reliance.
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Microsoft is challenging industry leaders with a new in-house cybersecurity AI model and an agentic system designed to lower costs.