Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-3770

Опубликовано: 07 авг. 2025
Источник: debian
EPSS Низкий

Описание

EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
edk2fixed2025.02-9package
edk2fixed2025.02-8+deb13u1trixiepackage
edk2no-dsabookwormpackage
edk2postponedbullseyepackage

Примечания

  • https://github.com/tianocore/edk2/security/advisories/GHSA-vx5v-4gg6-6qxr

  • only arch: amd64, other arch (particularly i386) are not affected

EPSS

Процентиль: 2%
0.00014
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
5 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.

redhat
5 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.

CVSS3: 7
nvd
5 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.

CVSS3: 7
msrc
5 месяцев назад

SMM IDT Privilege Escalation Vulnerability

CVSS3: 7
fstec
5 месяцев назад

Уязвимость среды с открытым исходным кодом для разработки UEFI EDK2, связанная с нарушением механизма защиты данных, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 2%
0.00014
Низкий