
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25250 is a Security Feature Bypass vulnerability in EAZ EazyFix version 12.9, classified under CWE-325 (Missing Cryptographic Step). The flaw allows a high-privileged local attacker to disable Secure Boot by circumventing a required cryptographic verification step, potentially enabling execution of unauthorized code during system boot. It was first disclosed by Microsoft on April 14, 2026, with NVD and GitHub Advisory Database entries published on August 27, 2026. The vulnerability carries a CVSS v3.1 base score of 6.0 (Medium) (GitHub Advisory, Microsoft MSRC).
The root cause is a missing cryptographic step (CWE-325) in EAZ EazyFix 12.9's Secure Boot disable functionality, mapped to CAPEC-68 (Subvert Code-signing Facilities). An attacker with local administrative privileges can exploit this flaw to bypass Secure Boot's cryptographic chain of trust, replacing or loading unsigned EFI bootloader components (specifically targeting paths such as X:\EFI\shdloader.efi and X:\EFI\Shield.efi) without triggering signature validation failures. Exploitation requires local access and high privileges, making it a local attack vector with low complexity. A public proof-of-concept repository provides detailed reproduction steps, including a vulnerable binary chain diagram and step-by-step boot chain explanation (GitHub PoC, GitHub Advisory).
Successful exploitation allows a high-privileged local attacker to disable Secure Boot, undermining the system's pre-OS integrity verification. This enables loading of unsigned or malicious bootloader code before the operating system initializes, potentially bypassing endpoint security controls, installing persistent bootkits, and exposing sensitive system data. Confidentiality and integrity impacts are rated High, while availability is unaffected; the scope is unchanged, meaning the impact is confined to the vulnerable component (GitHub Advisory, Microsoft MSRC).
A public proof-of-concept exploit is available on GitHub (TheMalwareGuardian/CVE-2026-25250), providing detailed lab setup instructions and a full attack chain walkthrough, assessed with high confidence as a real exploit (GitHub PoC). As of the latest available data, there is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.089% (0th percentile), indicating a low near-term exploitation probability. No specific threat actor attribution has been reported (GitHub Advisory).
X:\EFI\, where Secure Boot-related bootloader components reside.X:\EFI\shdloader.efi and X:\EFI\Shield.efi, which are part of the EazyFix Secure Boot enforcement chain.X:\EFI\shdloader.efi or X:\EFI\Shield.efi; presence of unsigned or unrecognized EFI binaries in the EFI system partition; new or altered bootloader files with mismatched timestamps.Microsoft released a security patch for this vulnerability as part of the April 2026 Patch Tuesday update (published April 14, 2026); organizations should apply this update immediately (Microsoft MSRC). As interim mitigations, restrict local administrative access to systems running affected Windows versions and EAZ EazyFix 12.9, implement UEFI firmware protections, and disable unnecessary Secure Boot modification interfaces where possible. Monitor environments for unauthorized Secure Boot state changes and audit EFI partition integrity regularly.
The vulnerability was covered in the context of Microsoft's April 2026 Patch Tuesday, which addressed 168+ vulnerabilities, with coverage from The Hacker News, Rapid7, Zero Day Initiative, and Lansweeper (Rapid7 Blog, ZDI Blog). ESET Research published a related analysis on forgotten UEFI shims undermining Secure Boot, providing broader context for this class of vulnerability (ESET Research). The Eclypsium podcast also discussed AI-powered firmware hacking and the future of vulnerability discovery in this space (Eclypsium).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."