The flaw is located in the GRUB2 Linux bootloader, but because of how Secure Boot is implemented, it can be used to compromise the booting process of Windows and other systems as well. Getting the patches that were announced today installed on all impacted computers and devices will require manual testing and deployment. It’s reasonable to expect that some systems will never be updated and will remain vulnerable to boot-level malware and rogue firmware modifications. The vulnerability triggers a full-blown GRUB audit vulnerability in the way GRub2 parses content from its configuration file.”]

