Home
MEDIUM: 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.17763.0 (custom) before 10.0.17763.8755
affected
10.0.19044.0 (custom) before 10.0.19044.7291
affected
10.0.19045.0 (custom) before 10.0.19045.7291
affected
10.0.22631.0 (custom) before 10.0.22631.7079
affected
10.0.22631.0 (custom) before 10.0.22631.7079
affected
10.0.26100.0 (custom) before 10.0.26100.8457
affected
10.0.26200.0 (custom) before 10.0.26200.8457
affected
10.0.28000.0 (custom) before 10.0.28000.2113
affected
10.0.17763.0 (custom) before 10.0.17763.8755
affected
10.0.17763.0 (custom) before 10.0.17763.8755
affected
10.0.20348.0 (custom) before 10.0.20348.5139
affected
10.0.25398.0 (custom) before 10.0.25398.2330
affected
10.0.26100.0 (custom) before 10.0.26100.32860
affected
10.0.26100.0 (custom) before 10.0.26100.32860
affected
Description
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Problem types
CWE-1329 - Reliance on Component That is Not Updateable
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41097 (Secure Boot Security Feature Bypass Vulnerability)