Executive brief
A security flaw in the Windows UEFI startup process could allow an authorized user to bypass critical system protections. UEFI is the foundational software that starts a computer before the operating system loads; if compromised, it can allow an attacker to disable security features or gain deep control over the machine. This could lead to a total loss of confidentiality and system integrity on the affected device.
Technical details
A protection mechanism failure (CWE-693) exists within the Microsoft Windows UEFI implementation. The vulnerability allows a locally authenticated attacker with low privileges to bypass established security boundaries during the boot process. By exploiting this flaw, an attacker can achieve high-impact gains in confidentiality, integrity, and availability, potentially leading to the execution of unauthorized code or the disabling of platform security features like Secure Boot. The attack requires local access but no user interaction. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Windows UEFI
Timeline
- 2026-06-09: advisory: Initial disclosure by Microsoft and NVD.