Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
A decade-old vulnerability in Microsoft-signed UEFI shims has left Secure Boot exposed, requiring urgent updates to prevent system bypasses.
🌍 Cross-language spread
This story first appeared in 🇪🇸 Spanish coverage — 21 minutes before PULSE detected it in English news.
Detected by matching proper nouns and figures that survive translation. Times reflect when each edition's coverage was first indexed.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
📍 How it ended
Following the discovery by ESET Research that old Microsoft-signed UEFI shims and forgotten bootloaders undermined Secure Boot for over a decade, Microsoft released updates to patch the bypasses. Windows 11 updates KB5101650 and KB5094126 specifically addressed the major flaw that had gone unnoticed since 2013.
Epilogue added 29d ago, after coverage quieted.
The brief
A critical security flaw has been identified within Microsoft's Secure Boot mechanism, allowing attackers to bypass system protections. According to reports from Ars Technica and The Hacker News, the vulnerability stems from 11 old, Microsoft-signed Linux UEFI shims and forgotten bootloaders. These specific applications were capable of undermining the Secure Boot process on affected devices. The breach remained unnoticed for over ten years, with TechSpot reporting that these bypasses had been hiding in plain sight since 2013. The flaw essentially created a blind spot in the boot process, exposing systems to potential exploitation by hackers using these forgotten, signed bootloaders. Extensive coverage from multiple technical outlets highlights the severity of the discovery. ESET Research is credited by The Manila Times and WeLiveSecurity as the entity that discovered the vulnerable UEFI shims.
Dark Reading and SC Media focus on how these forgotten bootloaders and old Microsoft-signed UEFI applications could be utilized to circumvent security protocols. The reporting emphasizes a significant gap in oversight, as HotHardware explicitly notes that the ability for hackers to bypass Secure Boot had existed for 11 years. The consensus across these outlets is that the vulnerability was a pervasive issue that escaped detection for over a decade despite the ubiquity of the affected software. To understand the context of this event, one must recognize the role of Secure Boot in establishing a chain of trust during the startup process. By using Microsoft-signed shims, the system ensures that only trusted code is executed. However, the existence of old, vulnerable shims meant that an attacker could use a legitimately signed but flawed bootloader to gain unauthorized access. This undermines the primary purpose of UEFI security, which is to prevent unauthorized software from loading before the operating system starts.
The fact that these shims remained valid for so long illustrates a failure in the revocation or updating process of signed boot components over the last decade. Moving forward, users must monitor for specific software updates to mitigate this risk. Neowin reports that Microsoft has released patches to address this major flaw, specifically naming Windows 11 updates KB5101650 and KB5094126. These updates are designed to fix the vulnerabilities that went unnoticed for more than ten years. The immediate priority for administrators and users is the deployment of these specific KB patches to close the Secure Boot blind spot. Future coverage will likely focus on whether these updates successfully revoke the compromised shims across all affected hardware platforms and if any active exploits of these 11 old shims have been detected in the wild.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 34d ago.
Quick answers
Who discovered the Secure Boot vulnerability?
ESET Research discovered the vulnerable UEFI shims that were undermining Secure Boot.
How long did this vulnerability exist?
Coverage indicates the flaw went unnoticed for over 10 years, with some reports stating it has been present since 2013 or for 11 years.
Which updates fix this issue for Windows 11 users?
The vulnerability is addressed in Windows 11 updates KB5101650 and KB5094126.
Coverage (9)
- Forgotten Bootloaders Expose Secure Boot Blind Spot Dark Reading · 46d ago
- Forgotten Microsoft-Signed Bootloaders Let Hackers Bypass Secure Boot For 11 Years HotHardware · 46d ago
- Windows 11 KB5101650, KB5094126 fixes major flaw that went unnoticed for over 10 years Neowin · 46d ago
- Microsoft finally patched Secure Boot bypasses that were hiding in plain sight since 2013 TechSpot · 46d ago
- ESET Research discovers vulnerable UEFI shims undermining devices’ Secure Boot The Manila Times · 46d ago
- Old Microsoft-signed UEFI applications can bypass Secure Boot SC Media · 46d ago
- 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot The Hacker News · 46d ago
- Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 46d ago
- Microsoft’s Secure Boot has been broken for a decade and no one noticed until now Ars Technica · 46d ago
Topics
Related trends
“We’re aware,” Microsoft on Windows 11 KB5120998 breaking the mouse cursor
1 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.
Microsoft, Palantir Lead Five Stocks Near Buy Points In Hot Sector
1 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
Microsoft, Stock Of The Day, Flashes New Buy Signal. Why It's Still An ‘AI Winner.'
5 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
‘It’s all you can hear’: New Jersey lawsuit takes on datacenter’s noise pollution
Vineland residents sue a Microsoft‑backed AI data center over nonstop noise and alleged illegal generator use.
Google, Microsoft and OpenAI among 100 firms calling for better cyber defences
2 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
Microsoft's latest AI rebrand beats its own history of terrible rebrands, renaming Microsoft 365 Roadmap to "AI at Work"
6 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.