Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the early boot process.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Clevo
Clevo notebook System Firmware |
|
Vendors & Products |
Clevo
Clevo notebook System Firmware |
Wed, 15 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 14 Oct 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the early boot process. | |
Title | Clevo UEFI firmware exposed Boot Guard private keys, enabling potential abuse of the Boot Guard trust chain | |
References |
|

Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-10-15T13:17:44.736Z
Reserved: 2025-10-10T02:08:14.733Z
Link: CVE-2025-11577

Updated: 2025-10-15T13:11:50.463Z

Status : Awaiting Analysis
Published: 2025-10-14T16:15:36.317
Modified: 2025-10-15T14:15:39.760
Link: CVE-2025-11577

No data.