Skip to content
Microsoft revokes legacy UEFI shims to prevent Secure Boot bypasses

Microsoft revokes legacy UEFI shims to prevent Secure Boot bypasses

Feeds.4Sysops IT News July 15, 2026

Microsoft has revoked 11 legacy, Microsoft-signed UEFI shim bootloaders that allowed attackers to bypass Secure Boot protections. These outdated binaries, primarily version 0.9 and earlier, remained trusted by the "Microsoft Corporation UEFI CA 2011" certificate despite containing long-known vulnerabilities. By utilizing a "Bring Your Own Vulnerable Bootloader" (BYOVB) attack, threat actors could execute unauthorized code during the early boot phase before the operating system initializes. Source

Extracted Entities

Attack Types (1)

Platforms (2)