CVE-2025-2296
published 2025-12-09CVE-2025-2296: EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability…
PriorityP350high8.4CVSS 4.0
AVNACLATNPRHUINVCLVIHVALSCLSIHSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.67%
47.8th percentile
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | edk2 | < edk2 2025.02-1 (forky) | edk2 2025.02-1 (forky) |
| msrc | azl3_edk2_20240524git3e722403cd16-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-25_on_azure_linux_3.0 | — | — |
| msrc | cbl2_edk2_20230301gitf80f052277c8-43_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_hvloader_1.0.1-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_qemu_6.2.0-26_on_cbl_mariner_2.0 | — | — |
| tianocore | edk2 | < edk2-stable202502 | edk2-stable202502 |
| tianocore | edk2 | >= 0 < 2025.02-1 | 2025.02-1 |
| tianocore | edk2 | >= 0 < 2025.02-1 | 2025.02-1 |
CVSS provenance
nvdv4.08.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.4HIGH
vendor_debian8.4HIGH
vendor_redhat8.4HIGH
vendor_msrc8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Un-verified kernel bypass Secure Boot mechanism in direct boot mode
vendor_msrc·2025-12-09·CVSS 8.2
CVE-2025-2296 [HIGH] CWE-20 Un-verified kernel bypass Secure Boot mechanism in direct boot mode
Un-verified kernel bypass Secure Boot mechanism in direct boot mode
Mariner: Mariner
TianoCore: TianoCore
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
edk2: EDK2: Improper Input Validation allows arbitrary command execution
vendor_redhat·2025-12-09·CVSS 8.4
CVE-2025-2296 [HIGH] CWE-20 edk2: EDK2: Improper Input Validation allows arbitrary command execution
edk2: EDK2: Improper Input Validation allows arbitrary command execution
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.
A flaw was found in EDK2 (EFI Development Kit 2). This vulnerability allows an attacker to cause arbitrary command execution and impact Confidentiality, Integrity, and Availability via improper input validation by local access.
Statement: This vulnerability is considered Important because it compromises a key security control in the boot chain, Secure Boot enforcement—by allowing an unsigned kernel to be load
Debian
CVE-2025-2296: edk2 - EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Inp...
vendor_debian·2025·CVSS 8.4
CVE-2025-2296 [HIGH] CVE-2025-2296: edk2 - EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Inp...
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2025.02-1)
sid: resolved (fixed in 2025.02-1)
trixie: resolved (fixed in 2025.02-1)
GHSA
GHSA-3f33-424w-8gqc: EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access
ghsa_unreviewed·2025-12-09
CVE-2025-2296 [HIGH] CWE-20 GHSA-3f33-424w-8gqc: EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.
OSV
CVE-2025-2296: EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access
osv·2025-12-09·CVSS 8.4
CVE-2025-2296 [HIGH] CVE-2025-2296: EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-2296 edk2: EDK2: Improper Input Validation allows arbitrary command execution [fedora-42]
bugzilla·2025-12-10·CVSS 8.4
CVE-2025-2296 [HIGH] CVE-2025-2296 edk2: EDK2: Improper Input Validation allows arbitrary command execution [fedora-42]
CVE-2025-2296 edk2: EDK2: Improper Input Validation allows arbitrary command execution [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to clo
Bugzilla
CVE-2025-2296 edk2: EDK2: Improper Input Validation allows arbitrary command execution
bugzilla·2025-12-09·CVSS 8.4
CVE-2025-2296 [HIGH] CVE-2025-2296 edk2: EDK2: Improper Input Validation allows arbitrary command execution
CVE-2025-2296 edk2: EDK2: Improper Input Validation allows arbitrary command execution
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:18465 https://access.redhat.com/errata/RHSA-2026:18465
Wiz
CVE-2025-2296 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2025-2296 [HIGH] CVE-2025-2296 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-2296 :
CBL Mariner vulnerability analysis and mitigation
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.
Source : NVD
## 8.4
Score
Published December 9, 2025
Severity HIGH
CNA Score 8.4
Affected Technologies
CBL Mariner
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 39.8
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
edk2-debuginfo
edk2-ovmf
Sources
NVD
CBL-Mariner 2.0 Sev
2025-12-09
Published