Impact
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both core and full installations).
Risk and Exploitability
With a CVSS score of 7.9, the vulnerability is considered high severity. The EPSS score is very low (<1%), indicating a low likelihood of exploitation; however, threat compared to remote exploits. The vulnerability is not listed in the CISA KEV catalog, indicating no widely known commercial exploitation at present.
OpenCVE Enrichment