Executive brief
Windows Secure Boot is a security feature that prevents unauthorized code from running during system startup. This vulnerability involves a flaw in a third-party component used by Secure Boot that allows an authorized attacker to bypass this protection locally. A successful exploit could allow an attacker with local access to disable or circumvent the boot-time security controls.
Technical details
This vulnerability stems from a dependency on a vulnerable third-party component within Windows Secure Boot. The flaw allows an authorized local attacker to bypass the Secure Boot security feature. The attack requires local access and prior authorization on the affected system. An attacker exploiting this could disable or circumvent boot-time security mechanisms. Microsoft has issued a security update to address this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed