cbcvebase.
CVE-2025-47827
published 2025-06-05

CVE-2025-47827: In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted…

PriorityP278medium4.6CVSS 3.1
AVPACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-11-04
Exploited in the wild
EPSS
3.82%
88.8th percentile
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
igeligel_os< 11.01.10011.01.100
microsoftwindows_10_1507< 10.0.10240.2116110.0.10240.21161
microsoftwindows_10_1607< 10.0.14393.851910.0.14393.8519
microsoftwindows_10_1809< 10.0.17763.791910.0.17763.7919
microsoftwindows_10_21h2< 10.0.19044.645610.0.19044.6456
microsoftwindows_10_22h2< 10.0.19045.645610.0.19045.6456
microsoftwindows_11_22h2< 10.0.22621.606010.0.22621.6060
microsoftwindows_11_23h2< 10.0.22631.606010.0.22631.6060
microsoftwindows_11_24h2< 10.0.26100.689910.0.26100.6899
microsoftwindows_11_25h2< 10.0.26200.689910.0.26200.6899
microsoftwindows_server_2012
microsoftwindows_server_2016< 10.0.14393.851910.0.14393.8519
microsoftwindows_server_2019< 10.0.17763.791910.0.17763.7919
microsoftwindows_server_2022< 10.0.20348.429410.0.20348.4294
microsoftwindows_server_2022_23h2< 10.0.25398.191310.0.25398.1913
microsoftwindows_server_2025< 10.0.26100.689910.0.26100.6899
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_21h2
msrcwindows_10_version_22h2
msrcwindows_11_version_22h2
msrcwindows_11_version_23h2
msrcwindows_11_version_24h2
msrcwindows_11_version_25h2

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for loading or insertion of the igel-flash-driver kernel module, which is the component that improperly verifies the cryptographic signature in this Secure Boot bypass.
  • Detect attempts to mount a SquashFS image as a root filesystem that has not passed cryptographic signature verification — indicative of exploitation of this vulnerability.
  • This vulnerability is confirmed actively exploited in the wild (KEV listed, Exploit Status: Exploited:Yes, Exploitation Detected). Prioritize detection on IGEL OS endpoints running versions before 11.
  • The vulnerability is classified as a 'use of a key past its expiration date' — hunt for use of expired signing keys in IGEL OS Secure Boot chain validation logs.
  • ·Vulnerability affects IGEL OS versions strictly before 11; systems running IGEL OS 11 or later are not affected by this specific Secure Boot bypass.
  • ·Microsoft Windows updates (KB5066586, KB5066782, KB5066791, KB5066793, KB5066835, KB5066780, KB5066837, KB5066836, KB5066875, KB5066873) incorporate mitigations for this IGEL OS vulnerability within the Windows Secure Boot ecosystem; these should be applied to address the Windows-side exposure.

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vulncheck4.6MEDIUM
cisa4.6MEDIUM
vendor_msrc4.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.