
Outdated Microsoft-Approved Startup Files Create a Backdoor Around Machine Boot Protections
Security researchers revealed eleven vintage bootloader programs that bypass hardware checks on modern PCs, prompting a targeted firmware blocklist update.
7 Oct 2026
When a personal computer powers on, a foundational security layer known as Secure Boot checks every incoming program to confirm it is legitimate before letting the operating system launch. Cybersecurity researchers at ESET recently discovered that eleven aging startup files, signed by Microsoft years ago, contain serious flaws that let malicious software sidestep this gatekeeper entirely.
The problem stems from how PC manufacturers configure device trust. To allow non-Windows software such as Linux distributions or repair disks to start smoothly on retail hardware, manufacturers preload a Microsoft third-party security certificate directly into motherboard firmware. As a result, any boot file stamped with that Microsoft signature is accepted as safe across hundreds of millions of computers worldwide.
Linux creators bridge the gap between their frequent software releases and Microsoft's centralized approval process by using a small middleman program called a shim. Microsoft inspects and signs this initial miniature loader, which then takes responsibility for validating the distributor's own secondary boot components and system core.
The eleven insecure files identified by researchers were built on shim version 0.9 or earlier. Because these packages were assembled nearly a decade ago, they contain ancient programming errors that modern protections were designed to stop.
The danger does not end with the shim code itself. These outdated tools were built to pass execution to secondary loaders, predominantly early editions of GRUB 2, which harbor their own catalogue of well-documented security loopholes, dramatically expanding the attack surface.

A computer does not even need to run an old operating system to fall prey to the issue. Because the motherboard's underlying firmware trusts Microsoft's third-party certificate by default, an intruder can simply supply an archive containing the vintage, signed shim on an external drive or through a local script to trigger the security bypass.
Once past the initial check, unverified software can seize control of the hardware before security utilities or the Windows kernel can initialize. This level of compromise clears the runway for stealthy bootkits, such as BlackLotus or Bootkitty, to embed themselves deep within the device where standard defensive software cannot find them.
Blocking these legacy files presents a physical challenge for hardware engineers. Firmware stores barred digital fingerprints inside a restricted memory pocket known as the revocation database, or dbx. Because storage capacity on motherboard chips is strictly limited to several dozen kilobytes, adding extensive lists of blocked files risks consuming critical space.
Newer boot software utilizes an approach called Secure Boot Advanced Targeting, which permits firmware to bar entire outdated version ranges with a single rule rather than logging every unique file fingerprint. Because these eleven discovered files predate such mechanisms, administrators must add their individual digital signatures to the forbidden inventory.
After initial notification in February 2026 coordinated through CERT/CC, Microsoft released firmware registry additions during its June 2026 security update to invalidate all eleven vulnerable executables. Keeping devices protected requires administrators to apply the latest motherboard blacklist updates so that firmware will refuse to execute the compromised files.