important · Boot chain — Windows
Windows Boot Manager has a newly recorded physical privilege-elevation path, but its trigger is undisclosed.
Affects
Microsoft Windows 10, Windows 11, and Windows Server systems using Windows Boot Manager.
Microsoft records physical access, no prior privileges and no user interaction, but supplies no CWE or technical path.
Detail and 2 sources
We do not know the resulting privilege, required boot configuration, or relationship to Secure Boot and BitLocker.
Chain to watch
Physically possess an affected Windows device→↓Reach an undisclosed Boot Manager validation or authorization failure→↓Obtain elevated privileges→↓The trigger, privilege transition and dependence on Secure Boot or BitLocker remain unknown.
Unverified chainDiff bootmgfw.efi and related boot binaries across the September build boundary, then test candidate paths with Secure Boot and BitLocker enabled.
Fixed builds exist, but the changed validation or authorization logic has not been established.