Impact
A missing cryptographic step in the Windows Boot Loader allows an attacker who already has local access to bypass a security feature that normally validates boot‑time code integrity. The flaw, categorized as CWE‑325, permits the attacker to sidestep the boot‑time restriction and execute otherwise disallowed code when the system starts, effectively escalating privileges or injecting malicious payloads at startup.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full installations and Server Core configurations.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is local privileged access, as the attacker must already have system access to exploit the missing cryptographic validation. The CVSS score of 6.0 indicates moderate severity, while the EPSS score of less than 1 % suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Though the exploit requires authorized local presence, environments with active privileged users face a heightened risk, but the overall likelihood of active attacks remains low at present.
OpenCVE Enrichment