Impact
An authorized local user can alter the Secure Boot configuration in a way that removes its integrity checks, allowing unsigned or malicious firmware or kernel components to load during boot. This flaw undermines the primary purpose of Secure Boot, which is to prevent the execution of tampered boot code, and can compromise the confidentiality and integrity of the entire system.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025. Both standard and Server Core installations on x86, x64, and ARM64 architectures are affected.
Risk and Exploitability
The CVSS score of 7.9 indicates moderate‑to‑high severity, while the EPSS score of 2 % reflects a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. It requires local, authorized access; once the bypass is achieved, an attacker can potentially install or run unsigned code during boot and gain elevated privileges, thereby facilitating further attacks on system confidentiality and integrity.
OpenCVE Enrichment