CVE-2026-48578

Published Jun 9, 2026

Last updated 3 days ago

CVSS high 7.9
Windows Secure Boot

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-48578 is a security feature bypass vulnerability found in Windows Secure Boot. It stems from a protection mechanism failure that allows an authorized attacker with local access to bypass a security feature. The vulnerability specifically involves a flaw in how the system validates certificate chains and manages trust relationships between security components. This enables an attacker to manipulate the boot process by substituting malicious certificates for legitimate ones, potentially leading to privilege escalation and the installation of persistent malware below the operating system level.

Description
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Modified
Products
windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.9
Impact score
5.8
Exploitability score
1.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-284

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.