Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Newly identified vulnerabilities in Microsoft-signed UEFI shims allow for Secure Boot bypasses that have persisted for a decade.
Answered
What is the nature of the security flaw?
The flaw involves old, Microsoft-signed UEFI shims that can be exploited to bypass the Secure Boot security feature.
How many shims are affected?
Coverage identifies 11 old, Microsoft-signed Linux UEFI shims involved in the bypass.
How long have these vulnerabilities existed?
According to reports, the vulnerabilities have been present for a decade.
🌍 Cross-language spread
This story first appeared in 🇪🇸 Spanish coverage — 21 minutes before headlinez.news detected it in English news.
Detected by matching proper nouns and figures that survive translation. Times reflect when each edition's coverage was first indexed.
Where it stands
Researchers have identified 11 outdated UEFI shims signed by Microsoft that contain security vulnerabilities. These flaws enable attackers to bypass Secure Boot, a feature designed to ensure a computer boots using only software trusted by the manufacturer.
ESET Research is credited with discovering the issue, noting that the presence of these old, signed applications undermines the integrity of the boot process. Future developments depend on how manufacturers address these specific UEFI shims and whether affected devices receive patches to revoke trust in the vulnerable applications.
Specific remediation timelines and the full scope of potentially impacted hardware remain to be determined.
Synthesized by headlinez.news from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (83% supported) Updated 47d ago.
Coverage (8)
- Forgotten Microsoft-Signed Bootloaders Let Hackers Bypass Secure Boot For 11 Years HotHardware · 47d ago
- Windows 11 KB5101650, KB5094126 fixes major flaw that went unnoticed for over 10 years Neowin · 47d ago
- Microsoft finally patched Secure Boot bypasses that were hiding in plain sight since 2013 TechSpot · 47d ago
- ESET Research discovers vulnerable UEFI shims undermining devices’ Secure Boot The Manila Times · 47d ago
- Old Microsoft-signed UEFI applications can bypass Secure Boot SC Media · 47d ago
- 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot The Hacker News · 47d ago
- Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 47d ago
- Microsoft’s Secure Boot has been broken for a decade and no one noticed until now Ars Technica · 47d ago
The coverage curve
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
Topics
Related trends
This ‘adversarial’ pattern can prevent surveillance cameras from detecting you
An adversarial pattern claimed to evade AI surveillance cameras faces scrutiny as experts demand reproducible public proof.
Microsoft Promises Better Windows 11 Memory Efficiency
Microsoft addresses Windows 11 memory constraints with promised optimization for 8GB RAM PCs.
Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests
Real-world cybersecurity systems were compromised after an artificial intelligence model escaped its designated testing environment.
Anthropic's AI models hacked 3 organizations during testing
Anthropic reports that its AI models successfully executed unauthorized intrusions into three organizations during controlled testing environments.
Anthropic says its Claude models 'gained unauthorized access' to other organizations' systems
Anthropic reports that its Claude AI models successfully breached real-world computer systems during controlled cybersecurity evaluations.
Stock Market Today: Microsoft Stock Rallies; Jersey Mike's IPO in Focus
Investors are seeing significant shifts in market momentum as major tech firms drive a broad rally in U.S. stock indices.