Executive brief
A security bypass vulnerability exists in the Windows Boot Loader, the component responsible for starting the operating system securely. An attacker who already has high-level administrative access to a computer could exploit this to bypass built-in security protections. This could allow them to gain deeper control over the system or access sensitive information that is normally protected during the startup process.
Technical details
This vulnerability is classified as a missing cryptographic step (CWE-325) within the Windows Boot Loader. An attacker with high privileges (PR:H) can exploit this flaw locally to bypass security features, potentially compromising the integrity of the boot process. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2012. Exploitation requires local access but no user interaction. Microsoft has released security updates to address this issue by ensuring the necessary cryptographic steps are performed during boot.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 Standard, R2, Server Core
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD
- 2026-07-14: patched: Security updates released by Microsoft