Логотип exploitDog
bind:CVE-2025-4275
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-4275

Количество 2

Количество 2

nvd логотип

CVE-2025-4275

8 месяцев назад

A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-v9r5-7mg9-fwrr

8 месяцев назад

Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-4275

A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-v9r5-7mg9-fwrr

Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched.

CVSS3: 7.8
0%
Низкий
8 месяцев назад

Уязвимостей на страницу