Researcher: 290+ MSI motherboards have firmware with a default UEFI Secure Boot setting that lets any OS run, even those with a wrong or missing signature
Bill Toulas / BleepingComputer :
Context & Ripple Effects
Secure Boot's core promise — that firmware only boots signed code — keeps breaking at the motherboard layer. Eclypsium's earlier finding that 271 Gigabyte models carried a firmware backdoor exposed how little verification happens between the vendor and the user, and Binarly later showed [[a:871658|Secure Boot fully compromised on 200+ models from Acer, Dell, Gigabyte, Intel, and Supermicro]] via a leaked cryptographic key.
The MSI report adds a different failure mode to the same arc: not an exploited flaw or leaked key, but a default configuration that leaves the protection effectively switched off out of the box. That matters because Microsoft's own patching cadence is already lagging — vulnerable boot binaries exploited by BlackLotus were fixed in 2022 but still not on a revocation list, so a board that boots anything unsigned compounds an existing enforcement gap.
First-order effects
- Owners of the affected 290+ MSI boards get no real Secure Boot protection unless they find and change the default setting manually, leaving the pre-boot environment open to unsigned bootkit malware of the BlackLotus type.
- MSI faces pressure to ship corrected firmware defaults or BIOS updates, the same remediation path Gigabyte took after Eclypsium flagged its 271-model backdoor.
Second-order effects
- Rival board makers — Gigabyte, ASRock, ASUS and peers in the same channel — can expect buyers and security researchers to audit their default Secure Boot configurations next, turning firmware defaults into a competitive differentiator.
- Enterprises and OEM integrators sourcing motherboards gain a new procurement check: verify Secure Boot state at imaging time rather than trusting the vendor's out-of-box configuration, adding cost to every deployment.
Third-order effects
- The pattern — misconfigured defaults on MSI, a backdoor on Gigabyte, leaked keys across Acer, Dell, Intel, and Supermicro — pushes the industry toward treating Secure Boot as a supply-chain property to be audited per device rather than a checkbox the vendor sets once.
- If defaults and key management keep failing, firmware assurance shifts to third-party verification and revocation infrastructure, with Microsoft's revocation-list discipline becoming the de facto gatekeeper of whether firmware patches actually protect anything.
The trend: PC firmware security is moving from trusting vendor-shipped Secure Boot defaults toward independently verified boot chains, as misconfigurations, backdoors, and key leaks keep eroding the mechanism's guarantee.