Up until just recently, some metrics of Microsoft Azure Attestation were completely vulnerable to spoofing in some circumstances, and would accept attacker controlled measurements. SecureBoot in this case, spoofed as ON from a malicious bootkit. see CVE-2026-45642