Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the early boot process.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Oct 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the early boot process. | |
Title | Clevo UEFI firmware exposed Boot Guard private keys, enabling potential abuse of the Boot Guard trust chain | |
References |
|

Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-10-14T15:34:09.651Z
Reserved: 2025-10-10T02:08:14.733Z
Link: CVE-2025-11577

No data.

Status : Awaiting Analysis
Published: 2025-10-14T16:15:36.317
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-11577

No data.

No data.