Executive brief
EazyFix is a Windows system recovery and snapshot tool used by home users, small businesses, and enterprises to quickly restore systems to previous states. A missing cryptographic step in version 12.9 allows an attacker to bypass Secure Boot security controls, potentially enabling unauthorized system modifications or malware persistence that could survive normal operating system restarts.
Technical details
The vulnerability is a security feature bypass (CWE-327: Use of a Broken or Risky Cryptographic Algorithm) caused by a missing cryptographic step in the Secure Boot disable mechanism. The affected component is the boot security validation in EazyFix 12.9. An attacker with local access can exploit this to circumvent Secure Boot protections without proper cryptographic verification. The attack vector requires local access and potentially administrative privileges. Successful exploitation allows an attacker to disable Secure Boot controls, which could facilitate the installation of boot-level malware or unauthorized firmware modifications. A fix is available in version 13 or later.
Affected products
- EAZ EazyFix 12.9
Timeline
- 2026-08-27: disclosed