logo

Microsoft WinRE Vulnerability Allows Hackers to Bypass UEFI/BIOS Password Enforcement

ID: b9de548b-928d-5389-9825-8fee50e630cc

STIX ID: report--b9de548b-928d-5389-9825-8fee50e630cc

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Divya

...
...

A newly disclosed WinRE vulnerability (CVE-2026-45585) can be abused via the UEFI BootNext NVRAM variable to bypass firmware pre-boot authentication on affected Windows 10/11 systems, enabling attackers with physical or administrative access to enter recovery environments, change boot settings, and potentially weaken protections like BitLocker; Microsoft and security experts recommend hardening recovery environments, enforcing TPM+PIN or startup keys, restricting NVRAM modifications, deploying EDR/measured boot, and improving physical security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.