PT-2025-41852 · Clevo · Clevo Uefi Firmware

Published

2025-03-20

·

Updated

2025-11-14

·

CVE-2025-11577

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Clevo UEFI firmware update packages, including B10717.exe
Description The UEFI firmware update packages inadvertently included private signing keys used for Boot Guard and Boot Policy Manifest verification. Exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, compromising the integrity of the early boot process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2026-00079
CVE-2025-11577

Affected Products

Clevo Uefi Firmware