Recently, Microsoft has fixed a Secure Boot bypass vulnerability that has existed since 2013. This vulnerability originated from old components bearing Microsoft's digital signature but not promptly revoked. Attackers could exploit these components to bypass UEFI Secure Boot protection and install malicious firmware on devices. This incident has exposed a serious issue in trust chain maintenance, namely the lack of effective tracking and revocation mechanisms for signed but flawed components.
