Executive brief
A security flaw in Windows Secure Boot could allow an attacker with administrative privileges to bypass critical startup protections. Secure Boot is designed to ensure a computer boots using only software that is trusted by the hardware manufacturer. If exploited, an attacker could undermine the integrity of the operating system, potentially allowing for the installation of persistent malware that survives OS reinstalls.
Technical details
A protection mechanism failure exists in the Windows Secure Boot implementation, categorized as a reliance on a component that is not updateable (CWE-1329). An attacker with high privileges (Administrator) and local access can exploit this vulnerability to bypass Secure Boot integrity checks. The vulnerability has a CVSS score of 7.9, reflecting a 'Changed' scope, meaning the exploit allows the attacker to impact components beyond the immediate software environment, such as the firmware-level boot process. This could lead to the execution of unsigned or malicious bootloaders. Microsoft has released an advisory and updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: advisory: Initial disclosure by Microsoft and NVD.