Target Industry

Indiscriminate, opportunistic targeting.

Overview

A new Secure Boot bypass vulnerability, tracked as CVE-2025-3052 (CVSS score 8.2), which can disable security on PCs and servers, allows bootkit malware installation. The vulnerability impacts nearly all systems that trust Microsoft’s “Unified Extensible Firmware Interface Certificate Authority (UEFI CA) 2011″ certificate.

Impact

The impact of CVE-2025-3052 is significant, as it can allow threat actors to disable Secure Boot protections, leading to unauthorised code execution and potential installation of bootkits. This can result in severe operational disruptions, financial losses, and reputational damage for organisations. The vulnerability can also facilitate further attacks, as it undermines the foundational security mechanisms of affected devices.

Affected Products

The vulnerability CVE-2025-3052 affects nearly all systems that trust Microsoft’s “UEFI CA 2011” certificate. This includes:

  • Windows PCs
  • Servers: Systems running Windows Server
  • Embedded Systems: Devices using UEFI firmware

Virtual Machines: VMs that rely on UEFI Secure Boot.

Exploitation

Exploitation of CVE-2025-3052 can occur when a threat actor with physical or administrative access invokes the vulnerable firmware flashing utility, allowing them to disable Secure Boot and execute unsigned code. The vulnerability can be exploited without user interaction, making it particularly dangerous. There is currently no public proof-of-concept.

Containment, Mitigations & Remediation

To mitigate CVE-2025-3052, organisations should apply the latest security patches released by Microsoft. Additionally, restricting administrative access, monitoring firmware settings, and implementing strong access controls are recommended. Regular audits of firmware and UEFI settings can also help in identifying and remediating vulnerabilities.

Threat Landscape

The threat landscape surrounding CVE-2025-3052 is characterised by a growing number of vulnerabilities targeting UEFI firmware. With threat actors increasingly leveraging these weaknesses to gain early execution and bypass security measures. The motivations of threat actors include financial gain, espionage, and disruption of services.

Further Information

Security Online article

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content