search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Clevo UEFI firmware embedded BootGuard keys compromising Clevo's implementation of BootGuard

Vulnerability Note VU#538470

Original Release Date: 2025-10-13 | Last Revised: 2025-10-16

Overview

Clevo’s UEFI firmware update packages included sensitive private keys used in their Intel Boot Guard implementation. This accidental exposure of the keys could be abused by an attacker to sign malicious firmware using Clevo’s Boot Guard trust chain, potentially compromising the pre-boot UEFI environment on systems where Clevo’s implementation has been adopted.

Description

Intel Boot Guard is a platform integrity technology, providing a root of trust that protects the earliest stages of the boot process. It cryptographically verifies the Initial Boot Block (IBB) and prevents the execution of untrusted firmware. Operating before UEFI is initialized, Boot Guard ensures that only authenticated firmware is executed during the earliest pre-boot stage. Boot Guard is often confused with UEFI Secure Boot, but Secure Boot operates later in the process, enforcing trust within the UEFI firmware execution phase and during the transition from UEFI to the operating system.

Clevo Co. is a computer hardware and firmware manufacturer that operates as both an Original Design Manufacturer (ODM) and an Original Equipment Manufacturer (OEM), producing laptops and UEFI firmware used by various personal computer brands. One of Clevo’s publicly released UEFI software executables included private keys integral to its Boot Guard trust chain. Because Clevo’s firmware is integrated into products from other manufacturers, the exposure may have supply chain implications extending beyond Clevo-branded systems.

Impact

An attacker with write access to flash storage for a system, whether through physical access or a privileged software update mechanism, could abuse the leaked keys to sign and install malicious firmware. Such firmware would be trusted at the early stages that will be protected by Boot Guard, allowing compromise of the affected UEFI systems and thus enabling persistent and stealthy control over the device.

Solution

While Clevo has reportedly removed the affected software containing the leaked keys, no public remediation steps have been announced by Clevo at this time. Users of Clevo-based devices, including those from other OEMs that integrate Clevo firmware, should: * Assess their exposure to affected firmware versions. * Monitor systems for unauthorized firmware modifications. * Apply firmware updates only from verified and trusted sources.

Acknowledgements

This issue was responsibly disclosed by the Binarly Research Team, with initial reporting by Thierry Laurion. This document was written by Vijay Sarvepalli.

Vendor Information

538470
 

American Megatrends Incorporated (AMI) Not Affected

Notified:  2025-07-22 Updated: 2025-10-16

Statement Date:   October 16, 2025

CVE-2025-11577 Not Affected

Vendor Statement

Not affected - AMI products do not contain these leaked keys

ASUSTeK Computer Inc. Not Affected

Notified:  2025-07-22 Updated: 2025-10-15

Statement Date:   October 15, 2025

CVE-2025-11577 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Google Not Affected

Notified:  2025-07-22 Updated: 2025-10-13

Statement Date:   July 23, 2025

CVE-2025-11577 Not Affected

Vendor Statement

Google Chrome OS systems do not use this BIOS Google Cloud Infra does not use this BIOS

Insyde Software Corporation Not Affected

Notified:  2025-03-26 Updated: 2025-10-13

Statement Date:   March 27, 2025

CVE-2025-11577 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Intel Not Affected

Notified:  2025-03-26 Updated: 2025-10-13

Statement Date:   April 02, 2025

CVE-2025-11577 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Phoenix Technologies Not Affected

Notified:  2025-07-22 Updated: 2025-10-13

Statement Date:   July 22, 2025

CVE-2025-11577 Not Affected

Vendor Statement

We have not received a statement from the vendor.

UEFI Security Response Team Not Affected

Notified:  2025-07-22 Updated: 2025-10-13

Statement Date:   August 05, 2025

CVE-2025-11577 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Acer Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

ADATA Unknown

Notified:  2025-03-26 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Amazon Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Clevo Unknown

Notified:  2025-06-24 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Dell Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Fujitsu Europe Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Fujitsu HQ Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Gamma Tech Computer Corp. Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

GETAC Inc. Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

GIGABYTE Unknown

Notified:  2025-03-26 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Hewlett Packard Enterprise Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

HP Inc. Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Lenovo Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Microsoft Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

ReactOS Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Star Labs Online Limited Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Supermicro Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

Toshiba Corporation Unknown

Notified:  2025-07-22 Updated: 2025-10-13

CVE-2025-11577 Unknown

Vendor Statement

We have not received a statement from the vendor.

View all 25 vendors View less vendors


Other Information

CVE IDs: CVE-2025-11577
API URL: VINCE JSON | CSAF
Date Public: 2025-10-13
Date First Published: 2025-10-13
Date Last Updated: 2025-10-16 14:16 UTC
Document Revision: 4

Sponsored by CISA.