← Back

CVE-2026-0390

nvd nist
Published: Apr 14, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

Affected (13)

7 products
Windows 10 1607
Windows 10 1809
Windows 10 21h2
Windows 10 22h2
Windows Server 2016
Windows Server 2019
Windows Server 2022
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Before 10.0.14393.9060
Before 10.0.14393.9060
Microsoft
Before 10.0.17763.8644
Before 10.0.17763.8644
Microsoft
Before 10.0.19044.7184
Before 10.0.19044.7184
Before 10.0.19044.7184
Microsoft
Before 10.0.19045.7184
Before 10.0.19045.7184
Before 10.0.19045.7184
Before 10.0.14393.9060
Before 10.0.17763.8644
Before 10.0.20348.5020

References (1)

Timeline

No history available yet.