Tekmono
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
No Result
View All Result
Tekmono
No Result
View All Result
Home News
Microsoft Patches Critical Windows Secure Boot Vulnerability

Microsoft Patches Critical Windows Secure Boot Vulnerability

by Tekmono Editorial Team
12/06/2025
in News
Share on FacebookShare on Twitter

Microsoft has released its June Patch Tuesday updates, addressing a critical vulnerability in Windows PCs that could allow attackers to bypass Secure Boot and install bootkits.

The flaw, identified as CVE-2025-3052, is a memory corruption issue that exploits Microsoft’s Secure Boot feature. Discovered by Binarly security researcher Alex Matrosov, the vulnerability is considered serious due to its potential to compromise system security at a fundamental level.

Matrosov explained, “Attackers can exploit this vulnerability to run unsigned code during the boot process, effectively bypassing Secure Boot and compromising the system’s chain of trust. Because the attacker’s code executes before the operating system even loads, it opens the door for attackers to install bootkits and undermine OS-level security defenses.”

Related Reads

Google opens applications for Gemini App Trusted Tester program

Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature

Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran

SpaceX acquires AI coding startup Cursor for $60 billion in strategic move

Bootkit malware is particularly dangerous as it runs before the operating system boots, allowing it to evade detection by standard security software. If successfully installed, bootkits can grant attackers full control of a PC, enable the installation of other malicious software, or facilitate access to confidential information.

Ironically, Microsoft implemented Secure Boot on Windows PCs precisely to prevent malware from loading during the boot-up process. This security feature is standard on modern PCs utilizing UEFI firmware, which replaced the older BIOS firmware.

The vulnerability allows an attacker to circumvent Secure Boot by signing a vulnerable UEFI application using Microsoft’s third-party certificates. This grants the unsigned code the ability to execute with elevated privileges during startup.

While the flaw itself has not been observed being actively exploited in the wild, the vulnerable application has been available since late 2022. Matrosov discovered the application on the VirusTotal security analysis website.

To mitigate the risk, Windows users are urged to install the latest updates. The process involves navigating to Settings, selecting Windows Update, and downloading the available patches. A reboot after installation will ensure the PC is protected.

June’s Patch Tuesday addresses a total of 66 security weaknesses across various Microsoft products, with nine of these rated as critical. In addition to CVE-2025-3052, another Secure Boot flaw, identified as CVE-2025-4275, was also patched. The updates also address a zero-day vulnerability listed as CVE-2025-33053.

ShareTweet

You Might Be Interested

Google opens applications for Gemini App Trusted Tester program
News

Google opens applications for Gemini App Trusted Tester program

17/06/2026
Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature
News

Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature

17/06/2026
Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran
News

Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran

17/06/2026
SpaceX acquires AI coding startup Cursor for  billion in strategic move
News

SpaceX acquires AI coding startup Cursor for $60 billion in strategic move

17/06/2026
Please login to join discussion

Recent Posts

  • Google opens applications for Gemini App Trusted Tester program
  • Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature
  • Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran
  • SpaceX acquires AI coding startup Cursor for $60 billion in strategic move
  • Qualcomm unveils Snapdragon Reality Elite as next-gen XR platform

Recent Comments

No comments to show.
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
Tekmono is a Linkmedya brand. © 2015.

No Result
View All Result
  • News
  • Guides
  • Lists
  • Reviews
  • Deals

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.