Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
(www.welivesecurity.com)
Problem being, of course, that you can add more certificates, but you can't revoke the original M$ one. And since it's vulnerable and you can't get rid, then these exploits still work and there's nothing you can do to stop it.