Executive brief
A security flaw in Windows Secure Boot could allow an attacker with administrative privileges to bypass critical startup protections. Secure Boot is designed to ensure that a computer boots using only software that is trusted by the hardware manufacturer. If exploited, an attacker could undermine the integrity of the operating system, potentially allowing for the installation of persistent malware that survives reboots and OS reinstalls.
Technical details
This vulnerability is classified as a protection mechanism failure (CWE-693) within the Windows Secure Boot process. An attacker with local access and high privileges (Administrator or equivalent) can exploit this flaw to bypass Secure Boot integrity checks. The vulnerability has a CVSS score of 7.9, notably featuring a Scope change (S:C), indicating that the exploit impacts components beyond the immediate security scope of the vulnerable software. Successful exploitation could allow for the execution of unsigned or malicious boot-level code. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory