VYPR

UEFI firmware update packages

by Clevo

CVEs (1)

  • CVE-2025-11577HigOct 14, 2025
    risk 0.49cvss 7.6epss 0.00

    Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected…