Microsoft's Secure Boot, an industry-wide standard designed to protect Windows and Linux devices from firmware infections, has been vulnerable to bypasses for over a decade. This critical flaw, discovered by ESET researchers, highlights a significant oversight in Microsoft's handling of 'shims' - a secondary trust anchor in the UEFI firmware. These shims, intended to extend Secure Boot to Linux and utility software, were left unsigned and accessible, allowing attackers to exploit them with relative ease. The issue lies in Microsoft's failure to revoke these shims despite known vulnerabilities, enabling attackers to subvert the mandated chain of digitally signed firmware and install malicious firmware that persists even after OS reinstallation or hard drive replacement. This threat extends to both Windows and Linux users, as the shim can be installed on devices running either operating system. The complexity of Secure Boot, with its reliance on multiple databases and revocation methods, further exacerbates the problem. The discovery of these vulnerable shims, some of which were used by major Linux distributors, underscores the need for a comprehensive review and update of the Secure Boot model. This incident serves as a stark reminder of the potential risks associated with complex security systems and the importance of proactive vulnerability management.