Target Industry
Indiscriminate, opportunistic targeting.
Overview
A new Secure Boot bypass vulnerability, tracked as CVE-2025-3052 (CVSS score 8.2), which can disable security on PCs and servers, allows bootkit malware installation. The vulnerability impacts nearly all systems that trust Microsoft’s “Unified Extensible Firmware Interface Certificate Authority (UEFI CA) 2011″ certificate.
Impact
The impact of CVE-2025-3052 is significant, as it can allow threat actors to disable Secure Boot protections, leading to unauthorised code execution and potential installation of bootkits. This can result in severe operational disruptions, financial losses, and reputational damage for organisations. The vulnerability can also facilitate further attacks, as it undermines the foundational security mechanisms of affected devices.
Affected Products
The vulnerability CVE-2025-3052 affects nearly all systems that trust Microsoft’s “UEFI CA 2011” certificate. This includes:
- Windows PCs
- Servers: Systems running Windows Server
- Embedded Systems: Devices using UEFI firmware
Virtual Machines: VMs that rely on UEFI Secure Boot.
Exploitation
Exploitation of CVE-2025-3052 can occur when a threat actor with physical or administrative access invokes the vulnerable firmware flashing utility, allowing them to disable Secure Boot and execute unsigned code. The vulnerability can be exploited without user interaction, making it particularly dangerous. There is currently no public proof-of-concept.
Containment, Mitigations & Remediation
To mitigate CVE-2025-3052, organisations should apply the latest security patches released by Microsoft. Additionally, restricting administrative access, monitoring firmware settings, and implementing strong access controls are recommended. Regular audits of firmware and UEFI settings can also help in identifying and remediating vulnerabilities.
Threat Landscape
The threat landscape surrounding CVE-2025-3052 is characterised by a growing number of vulnerabilities targeting UEFI firmware. With threat actors increasingly leveraging these weaknesses to gain early execution and bypass security measures. The motivations of threat actors include financial gain, espionage, and disruption of services.
Further Information













