Impact
The vulnerability arises from a dependency on a vulnerable third‑party component used during Windows Secure Boot. An attacker with authorized local access can exploit this flaw to bypass Secure Boot protections, ultimately enabling unsigned or malicious code to run during system boot. This bypass can compromise system integrity and may allow privileged persistence on the affected machine. The weakness is classified as CWE‑1395, highlighting the risk of trusting external components.
Affected Systems
Affected systems include Microsoft Windows 10 and Windows 11 desktop editions from versions 1607, 1809, 21H2, 22H2, 23H2, 24H2, 25H2, and 26H1 on both 32‑bit and 64‑bit platforms, as well as ARM64 variants where applicable. Server editions of Windows 2012, 2012 R2, 2016, 2019, 2022, and 2025—both full installations and Server Core variants—are also impacted. The issue spans x86, x64, and arm64 architectures as listed in the CNA data.
Risk and Exploitability
The CVSS base score of 4.4 indicates moderate risk, and the EPSS score of < 1% suggests a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploit in the wild yet. The likely attack vector is local, requiring authorized user or privileged access to the system. An attacker exposed to the vulnerable component could bypass Secure Boot, potentially elevating privileges or installing persistent malware before the operating system loads.
OpenCVE Enrichment