Junglewise Threat Intelligence

CVE-2026-41097: Microsoft Windows Secure Boot security feature bypass

CVE-2026-41097 · Severity: medium · CVSS 6.7 · Published 2026-05-12

Technologies: Microsoft Windows Secure Boot. Vendors: Microsoft.

Executive brief

A security flaw in Windows Secure Boot allows an attacker with administrative access to bypass critical boot-time protections. Secure Boot is designed to ensure that a computer starts up using only software that is trusted by the manufacturer. By exploiting this vulnerability, an attacker could potentially disable these safeguards to run unauthorized software or compromise the integrity of the operating system.

Technical details

This vulnerability is classified as a reliance on a component that is not updateable (CWE-1329) within the Windows Secure Boot architecture. An attacker with high privileges (Administrator) can exploit this flaw locally to bypass Secure Boot security features. Because the affected component cannot be updated through standard software patches, the vulnerability poses a persistent risk to the integrity of the boot process. Successful exploitation allows the attacker to circumvent protections intended to prevent the execution of untrusted bootloaders or firmware.

Affected products

  • Microsoft Windows Secure Boot

Timeline

  • 2026-05-12: disclosed: Initial publication by Microsoft and NVD.

References

Related threats