AI analysis
CVE-2026-6485 (CWE-489, active code left in production firmware) describes a UEFI Shell module embedded in the SPI Flash of affected UEFI BIOS images that can be used to bypass Secure Boot. An attacker with local access and high privileges (CVSS AV:L/PR:H) — for example a local administrator or someone with physical access — can run shell commands or execute startup scripts through the embedded shell, launching code that Secure Boot does not verify. The result is a break in the Secure Boot chain of trust, allowing unsigned or attacker-controlled code to run at boot (e.g., to install bootkit- or firmware-level persistence), which is why the CVSS scope is 'changed' (S:C) with high impact to confidentiality, integrity, and availability. Affected systems are those whose UEFI BIOS ships with this embedded UEFI Shell module in SPI Flash; the issue is tracked in CERT/CC VU#718077, but the exact vendor, product list, and version ranges are not specified in the available data. There is no known exploitation at this time: no public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates only a 0.1% chance of exploitation in the next 30 days.
What to do: Follow CERT/CC VU#718077 for vendor statements and apply the BIOS/firmware update from the affected BIOS vendor as soon as it is released; in the meantime, determine whether your fleet's BIOS images include an embedded UEFI Shell module in SPI Flash (via the vendor's documentation, boot menu, or a CHIPSEC/UEFI firmware audit). Where the BIOS setup allows, disable booting into the embedded UEFI Shell or execution of startup scripts, and restrict local administrative and physical access to sensitive systems, since the flaw requires high local privileges and is primarily a Secure Boot/persistence hardening risk rather than a remote threat.
Affected
| UEFI BIOS firmware with a UEFI Shell module embedded in SPI Flash | — |
Estimated exposure
unknown — no install-base data; plausibly anywhere from tens of thousands to millions of systems depending on how widely the affected firmware ships — No vendor, product line, or install counts are provided in the source data, and because the flaw is exploited locally with high privileges, internet-exposure scans cannot be used to size the affected population.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.