CVE-2026-25250
Received Received - Intake

Secure Boot Bypass in EAZ EazyFix 12.9

Vulnerability report for CVE-2026-25250, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: MITRE

Description

EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-28
AI Q&A
2026-08-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
eaz_solution eazyfix 12.9
eaz eazyfix 12.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-325 The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-25250 is a security feature bypass vulnerability in EAZ EazyFix 12.9. It involves a missing cryptographic step that allows Secure Boot to be disabled, potentially letting unauthorized changes to the system without proper validation.

Detection Guidance

Detection requires checking if Secure Boot is disabled or if unauthorized changes were made to boot configuration. Use commands like bcdedit /enum firmware or bcdedit /v to review boot configuration data. Look for Secure Boot being set to Off or unauthorized modifications to boot entries.

Impact Analysis

An attacker with local access could bypass Secure Boot protections, allowing them to install malicious software, disable security features, or gain persistent access to the system. This could lead to data theft, malware infections, or system compromise.

Compliance Impact

This vulnerability could violate compliance requirements that mandate Secure Boot or cryptographic integrity checks, such as GDPR's security principle or HIPAA's safeguards for protected health information. Non-compliance may result in penalties or legal consequences.

Mitigation Strategies

Enable Secure Boot in system firmware settings. Verify boot configuration integrity using bcdedit commands. Apply the latest Windows updates from Microsoft Update to patch the missing cryptographic step. Ensure all systems are updated to the latest version of EazyFix if applicable.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25250. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart