Three Microsoft Secure Boot Certificates Set to Expire on June 24, Posing Security Risk
Summary
Three Microsoft-signed certificates that underpin Secure Boot's chain of trust for verifying boot-time firmware and software will expire on June 24. This expiration could impact the security of Windows and Linux systems by potentially allowing UEFI bootkits—malware that runs before the OS and most antimalware—to bypass protections. Bootkits have a long history dating back to the early 1980s Apple II malware and later Windows-focused proofs of concept like BootRoot in 2005.
Source
Key quotes
· 4 pulledBeginning June 24, three Microsoft-signed certificates used to verify boot-time firmware and software will expire.
These certificates underpin Secure Boot's chain of trust, which validates digital signatures of all firmware loaded during system startup.
Secure Boot is intended to block UEFI bootkits that modify UEFI or BIOS and run before the operating system and most antimalware.
Such bootkits can steal credentials, create backdoors, and reinfect systems even after OS disinfecting or reinstallations.
You might also wanna read
Impending Expiration of Microsoft's Key for Linux Secure Boot Raises Concerns
Linux users with Secure Boot enabled may face issues as Microsoft's key used for signing the UEFI bootloader is set to expire in September.
Impending Issue for Linux Users with Secure Boot: Microsoft Key Expiration
Linux users with Secure Boot enabled may face issues as the key from Microsoft used to sign the UEFI bootloader is set to expire in Septembe
Understanding Secure Boot Certificate Rollover and Its Impact on Linux Users
The article discusses the implications of Secure Boot certificate rollover, particularly focusing on the claim that Linux users rely on a Mi
Technical Analysis: Circumventing UEFI Secure Boot Through Signed Bootloader Exploitation
The article discusses UEFI Secure Boot technology and methods to circumvent it by exploiting signed bootloaders. It explains that Secure Boo
Microsoft Confirms Windows 11 Security Update Causing Boot Failures on Some PCs
Microsoft has confirmed that the January 2026 Windows security update (released January 13) is causing boot failures on some PCs, with devic
windowscentral.com·4mo agoSecurity Vulnerabilities Discovered in HP 9000/720 Workstation Boot Loader Code
The article recounts a personal experience from 1999 when the author's company decommissioned an HP 9000/720 workstation. After the employee
