CVE-2025-4275

A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.
Configurations

No configuration.

History

30 Jul 2025, 08:15

Type Values Removed Values Added
Summary (en) Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched. (en) A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.

12 Jun 2025, 16:06

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-11 01:15

Updated : 2025-07-30 08:15


NVD link : CVE-2025-4275

Mitre link : CVE-2025-4275

CVE.ORG link : CVE-2025-4275


JSON object : View

Products Affected

No product.

CWE

No CWE.