Impact
The updated description confirms that Windows Secure Boot contains an improper access control flaw, enabling a local user with authorized privileges to bypass firmware verification and elevate their privileges.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both core and full installations).
Risk and Exploitability
With a CVSS score of 7.9, the vulnerability is considered high severity. The EPSS score is very low (<1%), indicating a low likelihood of exploitation; however threat compared to remote exploits. The vulnerability is not listed in the CISA KEV catalog, indicating no widely known commercial exploitation at present.
OpenCVE Enrichment