Impact
The CVE description states that no assigned CWE exists for a flaw in Windows Secure Boot that allows an authorized local attacker to bypass a security feature. The bypass enables the loading of unsigned drivers, firmware, or malware during boot, thereby compromising system integrity, confidentiality, and potentially elevating privileges.
Affected Systems
Affected systems include Microsoft Windows client releases: Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1, in ARM64, x86 and x64 where applicable. Server releases impacted are Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, both Standard and Server‑Core installations.
Risk and Exploitability
Based on the CVSS score of 7.9, the vulnerability has a high severity rating. The EPSS of 1% indicates that exploitation is unlikely but still feasible. The KEV status is not listed, suggesting no confirmed exploits yet. Exploitation requires local authorized privileges; an attacker must be able to modify UEFI settings or run software that can interact with the Secure Boot configuration. If the bypass is achieved, the attacker could achieve persistent, elevated access by loading malicious code during boot, presenting a significant long‑term compromise risk.
OpenCVE Enrichment