348
Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability
(www.theregister.com)
This is a most excellent place for technology news and articles.
So why can’t root add new keys?
The firmware has to allow it, so if you've got physical access to the machine that's possible. Remote access root, on the other hand, can't tell the firmware to register new keys as long as it's configured correctly