Executive brief
A security bypass vulnerability exists in the Windows Boot Manager, the component responsible for starting the operating system. An attacker with high-level administrative privileges on a local machine could exploit this to circumvent critical security protections, such as Secure Boot. This could allow for the installation of persistent malicious software that remains active even if the operating system is reinstalled.
Technical details
A protection mechanism failure (CWE-693) exists in the Microsoft Windows Boot Manager. The vulnerability allows an attacker with local access and high privileges (Administrator) to bypass security features, likely targeting Secure Boot or similar integrity checks. The CVSS vector indicates a 'Changed' scope (S:C), suggesting the bypass affects components beyond the Boot Manager itself, such as the underlying firmware or kernel integrity. Exploitation requires local physical or console access or a pre-existing high-privilege compromise. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Boot Manager All supported versions
Timeline
- 2026-06-09: disclosed: Initial disclosure by Microsoft and NVD.
- 2026-06-09: advisory: Microsoft Security Update Guide published.