An attacker with administrative access to a Windows machine with UEFI Secure Boot enabled may bypass code signing policy checks by putting intentionally-malformed configuration options in the boot configuration database (BCD).
26f375acd642d0f9a494693710868f2ef1b4b3531080dc3e3f2ac06389128d71