CyberzSOC

Publication detail
← Back to advisories & guidance

CSI: Guidance for Managing UEFI Secure Boot ↗ source

December 11, 2025 NSA Guidance

Summary

Recent vulnerabilities involving Secure Boot (e.g., PKFail [1], BlackLotus [2], BootHole [3], and similar unnamed [4]) have demonstrated the need to scrutinize the configuration of Secure Boot on enterprise devices. This document details instructions for system owners to query Secure Boot configuration, compare observed results to industry norms, and recognize and recover from misconfigurations. Organizations that neglect Secure Boot configuration may be at a greater risk of exposure to bootkits and other Checking the configuration of Secure Boot is also an important component of Supply Chain Risk Management (SCRM). Secure Boot is responsible for enforcing security policy at boot time based on a set of certificates and hashes placed within its data stores by system and operating system (OS) vendors. As the industry transitions away from 2011 signing certificates—that are nearing expiration—to new 2023 equivalents, there is even more need for organizations to scrutinize their Secure Boot configurations to ensure they are accurate and secure. U/OO/233483-25 | PP-25-4741 | December 2025 Ver. 1.0 Secure Boot was introduced to the Unified Extensible Firmware Interface (UEFI) industry standard in the mid-2000s.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-24932 6.7 Medium Microsoft Windows Server 2025 (Server Core installation) Secure Boot Security Feature Bypass Vulnerability
CVE-2022-21894 4.4 Medium Microsoft Windows 10 Version 1809 Secure Boot Security Feature Bypass Vulnerability

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.