A recent investigation by ESET has revealed a significant vulnerability in Microsoft's Secure Boot, a system designed to protect devices from firmware infections. For the majority of its existence—13 out of 14 years—Secure Boot has been susceptible to bypassing due to the presence of 11 defective firmware images, or 'shims,' that remained signed by Microsoft despite known vulnerabilities. This oversight allows even novice hackers to exploit the outdated shims to undermine the security protections embedded in the Unified Extensible Firmware Interface (UEFI) of devices.
The implications for businesses are considerable, as many organizations rely on Secure Boot as a foundational security measure for their computing infrastructure. The failure to revoke compromised firmware images emphasizes the importance of proactive cybersecurity practices and regular assessments of system integrity. Companies must ensure that their devices are not only equipped with security measures but also that these measures are actively managed and updated to address known vulnerabilities. This incident highlights a critical lesson in cybersecurity: the efficacy of security solutions is only as strong as their maintenance and oversight, particularly in an era increasingly reliant on AI and automated systems.
---
*Originally reported by [Schneier on Security](https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html)*