ZeroHour

CVE-2025-47827

KEV PoC large

Secure Boot Bypass via Expired Key in IGEL OS Before 11 (CVE-2025-47827)

CISA: IGEL OS Use of a Key Past its Expiration Date Vulnerability

CVSS 3.1
4.6 medium
EPSS
5%p92
Published
()
KEV added
AI analysis

CVE-2025-47827 is a Secure Boot bypass in IGEL OS before version 11, caused by improper verification of a cryptographic signature (CWE-347) in the igel-flash-driver module, which improperly validates a signature using a key past its expiration date. An attacker with physical access (CVSS vector AV:P) can boot a crafted root filesystem from an unverified SquashFS image, defeating the platform's Secure Boot guarantee and loading attacker-controlled code at boot time; the CVSS scoring assigns high availability impact. Deployments running IGEL OS 10 or earlier are affected; CISA's affected-product list names IGEL OS only, while the CPE data additionally tags Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (22H2-25H2) and Windows Server 2012/2016 releases, reflecting the shared Microsoft Secure Boot key ecosystem rather than a CISA-listed Microsoft impact. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-10-14, indicating confirmed in-the-wild exploitation, with ransomware use unknown and EPSS estimating a 4.9% (92nd percentile) probability of exploitation within 30 days. A public proof-of-concept is available (github.com/Zedeldi/CVE-2025-47827), and vendors/CISA have required mitigation per BOD 22-01 guidance.

What to do: Inventory all IGEL endpoints and upgrade any running OS 10 or earlier to IGEL OS 11 (current 11.x) per vendor instructions, which is the required KEV/BOD 22-01 remediation path. Because the attack requires physical access (AV:P), restrict physical and console access to thin clients in exposed locations such as lobbies, clinical areas and production floors, and inspect any device that may have been accessed for signs of root-filesystem tampering or unexpected boot behavior. The public PoC (Zedeldi/CVE-2025-47827) can be used to verify whether devices still boot an unverified SquashFS image.

Affected
IGEL OSall versions before 11 (i.e., OS 10 and earlier) - listed as affected by CISA
microsoft Windows 101507, 1607, 1809, 21H2, 22H2 (tagged in CPE; CISA's affected list names only IGEL OS)
microsoft Windows 1122H2, 23H2, 24H2, 25H2 (tagged in CPE; CISA's affected list names only IGEL OS)
microsoft Windows Server2012, 2016 (tagged in CPE; CISA's affected list names only IGEL OS)
Estimated exposure
largeon the order of 100,000-1,000,000 IGEL endpoints (residual pre-v11 share of IGEL's multi-million-device installed base) - estimate — IGEL OS is a widely deployed thin-client/edge OS in enterprise VDI estates with a vendor-cited installed base in the millions of endpoints, but only devices still running OS 10 or earlier are affected, and the vendor does not publish…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

CISA Known Exploited Vulnerability
Affected
IGEL IGEL OS
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
igelmicrosoft
Products
igel os, windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2012, windows server 2016
Weakness
CWE-347
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news