Junglewise Threat Intelligence

CVE-2026-48578: Microsoft Windows Secure Boot protection mechanism failure

CVE-2026-48578 · Severity: high · CVSS 7.9 · Published 2026-06-09

Technologies: Microsoft Windows Secure Boot. Vendors: Microsoft.

Executive brief

A security flaw in Windows Secure Boot could allow an attacker with administrative privileges to bypass critical boot-time protections. Secure Boot is designed to ensure that a computer boots using only software that is trusted by the hardware manufacturer. If exploited, an attacker could potentially install persistent malicious software that remains hidden even if the operating system is reinstalled.

Technical details

A protection mechanism failure exists in Windows Secure Boot, classified as improper access control (CWE-284). The vulnerability allows a local attacker with administrative or high-level privileges (PR:H) to bypass Secure Boot integrity checks. By successfully exploiting this flaw, an attacker can undermine the Root of Trust and potentially execute unsigned or malicious code during the boot process. The vulnerability has a CVSS score of 7.9, reflecting a high impact on confidentiality and integrity with a scope change (S:C), though it requires local access. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Windows Secure Boot

Timeline

  • 2026-06-09: advisory: Advisory published by Microsoft and NVD.

References

Related threats