The issue affects 11 shim binaries that were still signed and accepted by systems enforcing Secure Boot. That signature is what allows code to run during the...

Eleven old Microsoft-signed UEFI shims could let admin-level attackers bypass Secure Boot and run code before the operating system loads

Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple.