Executive brief
A security issue exists in how Windows manages Secure Boot, a feature that ensures your computer only starts up using trusted software. Several critical digital certificates used to verify the identity of the Windows boot process are set to expire in mid-2026. If these certificates are not updated correctly, devices may lose important security protections or fail to boot properly, potentially allowing unauthorized software to run during the startup process.
Technical details
This vulnerability involves a reliance on non-updateable or difficult-to-update components (CWE-1329) within the UEFI Secure Boot framework. Specifically, the Microsoft Corporation KEK CA 2011, UEFI CA 2011, and Windows Production PCA 2011 certificates stored in the UEFI Key Exchange Key (KEK) and Signature Database (DB) are nearing expiration. The update process for these certificates relies on firmware components that may contain defects, leading to unpredictable behavior or failure to rotate the trust anchors. An attacker with high privileges could potentially exploit a disrupted trust chain to bypass Secure Boot protections. Microsoft has released updates for various Windows and Windows Server versions to facilitate the certificate rotation.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2012 Standard, Server Core
Timeline
- 2026-01-13: advisory: Initial disclosure by Microsoft