CVE-2025-3052Untrusted Pointer Dereference in Research Biosflashshell

Severity
8.2HIGHNVD
EPSS
0.1%
top 78.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10
Latest updateAug 27

Description

An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 1.5 | Impact: 6.0

Affected Packages17 packages

🔴Vulnerability Details

1
GHSA
GHSA-q4rv-v64c-3hff: An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software2025-06-10

📋Vendor Advisories

2
Red Hat
vulnerable-uefi-module: Arbitrary write in UEFI module could lead to bypassing Secure Boot2025-06-11
Microsoft
Cert CC: CVE-2025-3052 InsydeH2O Secure Boot Bypass2025-06-10

🕵️Threat Intelligence

4
Securelist
Exploits and vulnerabilities in Q2 20252025-08-27
Securelist
Vulnerability landscape analysis for Q2 20252025-08-27
Bleepingcomputer
New Secure Boot flaw lets attackers install bootkit malware, patch now2025-06-10
Bleepingcomputer
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws2025-06-10