Windows Secure Boot Certificate Expiry Exposes Billions of PCs to Bootkit and Firmwar
#1
Information 
Quote:Microsoft’s long-planned Secure Boot certificate rollover has reached a critical milestone, impacting more than just routine updates.

The Microsoft Corporation KEK CA 2011 expired on June 24, 2026, the Microsoft UEFI CA 2011 expires on June 27, 2026, and the Microsoft Windows Production PCA 2011 is scheduled to expire on October 19, 2026. This requires organizations to transition firmware trust from the 2011 certificate chain to the 2023 replacements.

This transition is important because Secure Boot is part of the pre-OS trust path, where UEFI firmware validates boot components before loading Windows or Linux. Therefore, certificate expiry becomes a firmware security issue rather than merely an endpoint patching task.

Windows Secure Boot Certificate Expiry Exposes PCs

At the core of the issue is Secure Boot’s layered trust hierarchy. UEFI firmware relies on the Platform Key to authorize the Key Enrollment Key (KEK), which is used to sign updates to the allowed signature database (DB) and the revocation database (DBX), as per reported by CSN.

During startup, the firmware checks whether bootloaders and EFI components are trusted in the DB and not blocked in the DBX before allowing execution. Microsoft has stated that devices that miss the 2023 certificate transition will still boot and run existing software.

However, they will lose access to future Windows Boot Manager protections, updates to Secure Boot DB and DBX, and new mitigations against boot-level threats.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
WhatsApp Adds Security Warning Before Us...
WhatsApp has intro...harlan4096 — 08:21
uBOLite 2026.625.1633
uBOLite 2026.625.1...harlan4096 — 07:35
7-Zip 26.02
7-Zip 26.02 Wha...harlan4096 — 07:23
AMD to bring back Ryzen 7 5800X3D as AM...
AMD has officially r...harlan4096 — 07:12
Windows Secure Boot Certificate Expiry E...
Microsoft’s long-p...harlan4096 — 07:04

[-]
Birthdays
Today's Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>