“Attackers can exploit this vulnerability to run unsigned code during the boot process, effectively bypassing Secure Boot and compromising the system’s chain of trust.”
A BIOS flasher for one vendor’s rugged tablets was signed with the Microsoft certificate nearly every PC trusts. It writes to memory wherever an NVRAM variable tells it to, before the OS loads. It sat on VirusTotal for months. Secure Boot is only as strong as the worst binary Microsoft ever signed.