Secure Boot Key Flaw Exposes Windows Devices to Attack: Report

Advertisement
By Sanket Vijayasarathy | Updated: 11 August 2016 16:31 IST
Highlights
  • Secure Boot policies are signed and validated by Microsoft
  • The leaked golden key can bypass operating system checks
  • Golden key allows attackers to boot any OS or self-signed binary

A leak has gone horribly wrong for Microsoft and the company is scrambling to fix the mess. Microsoft unwittingly leaked a 'golden key' that can unlock Windows-powered PCs, tablets, and phones protected by Secure Boot.

For the uninitiated, Secure Boot, a part of Unified Extensible Firmware Interface (UEFI), secures every component of a device's boot process by checking it is validated and signed by Microsoft. This protects the system from being booted by any other OS (malicious or non-malicious) an attacker or user wants to install. Secure Boot, once enabled, cannot be disabled by the user due to policies that are also validated by Microsoft and are loaded and obeyed once the Windows startup process is executed.

Microsoft, however, allowed an exception to the rule that has since become a nightmare for the company. The tech giant signed a special Secure Boot policy that disables the operating system checks, meant to allow developers to test new operating systems without having to sign each one. This policy essentially bypasses the standard checks.

Advertisement

Understandably, the special policy isn't available on commercial products. However, it has been leaked online - where it is now available for attackers to misuse. A curious person may find this 'golden key' - which essentially allows a backdoor into a Secure Boot-enabled Windows system - load it into a Windows firmware and trick Microsoft into believing the person is loading a valid and verified OS while actually installing a malicious one, even a self-signed binary. In simple terms, the golden key can unlock Secure Boot, and gives attackers unfettered access to install bootkits or rootkits alongside.

Advertisement

Security researchers my123 (@never_released) and slipstream (@TheWack0lian) were the ones to warn Microsoft that its Windows machines products were vulnerable due to the leak. After months of ignoring the issue, the researchers said Microsoft issued a bug bounty award and created two patches (one in July, and another in August). The Register claimed even the second patch does not actually resolve the vulnerability, only removing access to certain boot manager systems while leaving the policy flaw intact.

A third patch is expected to come out in September. However, the researchers believe the vulnerability cannot be completely fixed. Until the third patch comes out, the only thing users can do to protect their systems is to make sure their Microsoft patches are up-to-date on all Windows devices.

Advertisement

The leak of the golden key signals a bigger threat, one which puts into question the safety and security of devices and the need for such backdoor entries that can render your phones and computers vulnerable to hacks. To this effect, one of the researchers, Slipstream, issued a statement to the FBI:

"About the FBI: are you reading this? If you are, then this is a perfect real world example about why your idea of backdooring cryptosystems with a "secure golden key" is very bad! Smarter people than me have been telling this to you for so long, it seems you have your fingers in your ears. You seriously don't understand still? Microsoft implemented a 'secure golden key' system. And the golden keys got released from MS own stupidity. Now, what happens if you tell everyone to make a 'secure golden key' system?"
 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  2. Infinix Note 60 Ultra With Pininfarina Design Launched at MWC 2026
  3. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  4. Nothing Phone 4a, Phone 4a Pro Launched in India at This Price
  5. Nothing Phone 4a vs Phone 3a: Price in India, Specifications Compared
  6. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  7. Nothing Launches Headphone (a) With Adaptive ANC, Spatial Audio Support
  8. Just a Day After Releasing GPT-5.3 Instant, OpenAI Teases GPT-5.4 Model
  9. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  10. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  1. OpenAI’s Codex App Is Now Available on Windows, Can Be Downloaded via Microsoft Store
  2. OpenAI Teases GPT-5.4 AI Model Launch Just a Day After Releasing GPT-5.3 Instant
  3. Nothing Headphone (a) Launched With Adaptive ANC, Customisable Controls: Price, Specifications
  4. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  5. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  6. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  7. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
  8. Samsung Patent Hints at Potential Clamshell-Style Foldable With Two Cover Displays
  9. Google Introduces Gemini 3.1 Flash-Lite as Its Fastest and Most Cost-Efficient AI Model
  10. Nothing Phone 4a Launched in India With Glyph Bar Interface Alongside Nothing Phone 4a Pro: Price, Specs
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.