Junglewise Threat Intelligence

CVE-2026-45588: Microsoft Windows Secure Boot protection mechanism failure

CVE-2026-45588 · Severity: high · CVSS 7.9 · Published 2026-06-09

Technologies: Microsoft Windows Secure Boot. Vendors: Microsoft.

Executive brief

A security bypass vulnerability exists in Windows Secure Boot, a feature designed to ensure that a device boots using only software that is trusted by the Original Equipment Manufacturer. An attacker with administrative privileges could exploit this flaw to bypass boot-time security protections. This could allow for the installation of persistent malware that survives operating system reinstalls or the unauthorized modification of low-level system components.

Technical details

A protection mechanism failure (CWE-693) exists in the Windows Secure Boot implementation. The vulnerability allows a local attacker with high privileges (Administrator) to bypass Secure Boot integrity checks without user interaction. By successfully exploiting this flaw, an attacker can compromise the boot chain and potentially gain persistent control over the system firmware or kernel environment. The vulnerability is tracked as CVE-2026-45588 and has a CVSS 3.1 base score of 7.9, reflecting the impact on confidentiality and integrity across security scopes. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Secure Boot

Timeline

  • 2026-06-09: advisory: Initial disclosure by Microsoft and NVD
  • 2026-06-09: patched: Security update released by Microsoft

References

Related threats