Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr99-8qv3-wr9x

Опубликовано: 14 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the early boot process.

Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the early boot process.

EPSS

Процентиль: 7%
0.00027
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
nvd
4 месяца назад

Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the early boot process.

CVSS3: 2.4
fstec
11 месяцев назад

Уязвимость компонента Bootguard микропрограммного обеспечения UEFI-прошивок ноутбуокв Clevo, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 7%
0.00027
Низкий

7.6 High

CVSS3