Eleven legacy Linux UEFI shims that still carry Microsoft signatures have been identified as possible paths to a Secure Boot bypass, showing how revocation gaps can turn trusted boot code into a liability.