Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the early boot process.
History

Tue, 14 Oct 2025 15:45:00 +0000

Type Values Removed Values Added
Description Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the early boot process.
Title Clevo UEFI firmware exposed Boot Guard private keys, enabling potential abuse of the Boot Guard trust chain
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2025-10-14T15:34:09.651Z

Reserved: 2025-10-10T02:08:14.733Z

Link: CVE-2025-11577

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-14T16:15:36.317

Modified: 2025-10-14T19:36:29.240

Link: CVE-2025-11577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.