Executive brief
A security flaw in Windows Secure Boot could allow an attacker with administrative privileges to bypass critical boot-time protections. Secure Boot is designed to ensure that a computer boots using only software that is trusted by the hardware manufacturer. If exploited, an attacker could potentially undermine the integrity of the operating system and gain persistent control over the device that survives standard security measures.
Technical details
A protection mechanism failure exists in Windows Secure Boot, classified as improper access control (CWE-284). The vulnerability allows a local attacker with high privileges (Administrator) to bypass Secure Boot integrity checks. By successfully exploiting this flaw, an attacker can load unauthorized software during the boot process, potentially leading to the installation of bootkits or other persistent malware that operates outside the visibility of the operating system. The attack requires local access and high-level permissions but results in a scope change (S:C), impacting the underlying hardware/firmware trust boundary. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Windows Secure Boot
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory