CVE-2025-47827
IGEL · Published June 5, 2025
4.6
CVSS v3.1
MEDIUMCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.
Affected Products
- Igel OS < 11.01.100
- Windows 10 1507 < 10.0.10240.21161
- Windows 10 1607 < 10.0.14393.8519
- Windows 10 1809 < 10.0.17763.7919
CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H