CVE-2025-47827
9.5 CISA KEVIGEL · IGEL OS
A Secure Boot bypass vulnerability exists in the IGEL OS igel-flash-driver, allowing attackers with physical access to execute arbitrary code by mounting an unverified SquashFS image.
Executive summary
This critical Secure Boot bypass vulnerability in IGEL OS is currently being actively exploited in the wild and enables kernel-level code execution.
Vulnerability
The vulnerability exists due to improper verification of cryptographic signatures within the igel-flash-driver module. An unauthenticated attacker with physical access can bypass Secure Boot protections to mount a crafted, unverified SquashFS image, leading to arbitrary code execution at the kernel level.
Business impact
With a CVSS score of 9.5, this vulnerability represents a critical risk to organizational integrity. Successful exploitation allows an attacker to compromise the root filesystem, gain kernel-level privileges, and deploy persistent rootkits. This bypass undermines the entire chain of trust for the endpoint, potentially leading to full system takeover and unauthorized access to sensitive data processed on the device.
Remediation
Immediate Action: Update all affected systems to IGEL OS version 11.01.100 or later. Additionally, apply Microsoft Windows update KB5066791 to update the Secure Boot revocation list (DBX) with the compromised IGEL component signatures.
Proactive Monitoring: Monitor physical access logs for high-security environments and audit endpoints for unauthorized modification of boot configuration or unexpected filesystem mounts.
Compensating Controls: Restrict physical access to hardware devices and ensure that BIOS/UEFI settings are password-protected to prevent unauthorized boot sequence modifications.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository is available at https://github.com/Zedeldi/CVE-2025-47827.
Analyst recommendation
The presence of this vulnerability in the CISA Known Exploited Vulnerabilities catalog necessitates immediate attention. Organizations must prioritize the deployment of the specified IGEL OS updates and the associated DBX revocation list updates across all managed devices. Failure to remediate this flaw leaves hardware vulnerable to sophisticated rootkit deployment and permanent system compromise.