Executive brief
A security flaw in Windows Secure Boot could allow an attacker with administrative privileges to bypass critical boot-time protections. Secure Boot is designed to ensure that a computer boots using only software that is trusted by the hardware manufacturer. If successfully exploited, an attacker could undermine the integrity of the operating system, potentially allowing for the installation of persistent malware that survives system reboots.
Technical details
This vulnerability is classified as a protection mechanism failure (CWE-693) within the Windows Secure Boot process. An attacker with local access and high privileges (Administrator or equivalent) can exploit this flaw to bypass Secure Boot integrity checks. The vulnerability has a CVSS score of 7.9, reflecting a high impact on system confidentiality and integrity due to the 'Changed' scope, which indicates the attacker can impact components outside the immediate security scope of the vulnerable software. This could lead to the execution of unsigned or malicious bootloaders. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Windows Secure Boot
Timeline
- 2026-06-09: disclosed: Vulnerability published by Microsoft and NVD.