PT-2025-41852 · Clevo · Clevo Uefi Firmware

CVE-2025-11577

·

Published

2025-03-20

·

Updated

2025-11-14

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Clevo UEFI firmware update packages, including B10717.exe
Description The UEFI firmware update packages inadvertently included private signing keys used for Boot Guard and Boot Policy Manifest verification. Exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, compromising the integrity of the early boot process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00079
CVE-2025-11577

Affected Products

Clevo Uefi Firmware