VYPR
advisoryPublished Jul 29, 2026· 1 source

Microsoft Secure Boot Vulnerability Existed for 13 Years

A critical flaw in Microsoft's Secure Boot mechanism, designed to protect against firmware infections, has been exploitable for 13 of its 14 years of existence.

Microsoft's Secure Boot, a cornerstone technology intended to safeguard devices from malicious firmware, has been undermined by a long-standing vulnerability, according to researchers at ESET. The security firm discovered that 11 firmware images, some dating back to 2013, were digitally signed by Microsoft despite containing known defects. These signed images, known as 'shims,' are crucial for extending Secure Boot's protection to operating systems like Linux and for utility software.

The vulnerability allows even novice attackers to bypass the Unified Extensible Firmware Interface (UEFI) protection embedded in a device's motherboard. The exploit is reportedly simple to execute, rendering the core security feature ineffective for a significant portion of its lifespan. This oversight stems from Microsoft's failure to revoke these vulnerable shims after their flaws were identified, leaving systems susceptible for over a decade.

Secure Boot is designed to ensure that only trusted software is loaded during the boot process, preventing rootkits and other firmware-level malware from compromising a system before the operating system even starts. By signing these defective shims, Microsoft inadvertently provided a backdoor that could be exploited to load untrusted code, effectively negating the intended security benefits.

The implications of this discovery are far-reaching, potentially affecting millions of devices that rely on Secure Boot for their foundational security. While the article does not specify which versions of Windows or Linux are most affected, the age of some of the vulnerable shims suggests a broad impact across various hardware generations.

ESET's research highlights a critical lapse in Microsoft's firmware signing and revocation process. The company is responsible for vetting and signing these shims to ensure compatibility and security for non-Windows operating systems. The continued presence of known-vulnerable code under Microsoft's signature represents a significant failure in this oversight.

While Microsoft has not yet issued a formal statement or patch for this specific issue, the company typically addresses such vulnerabilities through its regular security updates. Users and organizations are advised to monitor Microsoft's security advisories for any forthcoming guidance or mitigation steps. The long-term nature of this vulnerability underscores the importance of continuous monitoring and proactive management of firmware components.

This incident raises questions about the efficacy of long-term firmware security management and the challenges in maintaining the integrity of digital signing processes over extended periods. The discovery serves as a stark reminder that even foundational security technologies can harbor deep-seated flaws that remain undetected or unaddressed for years.

Synthesized by Vypr AI