Impact
This vulnerability allows an attacker who gains physical access to a device to manipulate the Windows Boot Manager and acquire higher privileges on the affected operating system. The flaw results from a missing protection against unauthorized modification or use of the boot code, which is classified as CWE-693. An attacker can use the exploit to run code with elevated privileges, potentially compromising the confidentiality, integrity, and availability of the system and any data or services it hosts.
Affected Systems
Microsoft Windows operating systems and servers are affected, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Core installations).
Risk and Exploitability
The vulnerability scores a CVSS 6.8, indicating a moderate severity. EPSS data is unavailable, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be physical access, as the description explicitly states a physical attack is required. No public patch is currently available, so mitigation relies on restricting physical access and hardening boot security.
OpenCVE Enrichment