Impact
Improper access control in Windows Secure Boot allows an authorized local attacker to bypass the Secure Boot enforcement, enabling the installation or execution of unsigned firmware or boot components.
Affected Systems
Affected workloads are Microsoft Windows 11 versions 24H2, 25H2, and 26H1 on both ARM64 and x64 architectures, along with Windows Server 2025, including Server Core installations.
Risk and Exploitability
The CVSS score is 7.9 and the EPSS score is <1%. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local and requires authenticated access to the system. The potential impact is limited to the ability to bypass Secure Boot enforcement, which could allow the installation of unsigned code or firmware during the boot process.
OpenCVE Enrichment