Impact
An authorized local attacker can exploit a flaw in Windows Secure Boot that bypasses the secure boot enforcement feature. This omission lets the system load components that are not verified by the UEFI firmware, undermining the integrity guarantees that Secure Boot is designed to provide.
Affected Systems
Affected releases include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 in both standard and Server Core configurations, across x86, x64, and ARM64 architectures where applicable.
Risk and Exploitability
The CVSS score of 7.9 classifies the vulnerability as high severity, while an EPSS score of 1% indicates a low but non‑zero likelihood of exploitation. The CVE is not listed in CISA’s KEV catalog, meaning no confirmed public exploits are known. Exploitation requires local, authorized access; once the Secure Boot bypass is achieved, the system’s boot integrity can be compromised.
OpenCVE Enrichment