CVE-2025-4275: SecureFlashDxe: Incorrect UEFI variable attributes check allows usage of invalid certificate
A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4275?
CVE-2025-4275 has been classified with a high severity level due to its potential impact on system security.
How do I fix CVE-2025-4275?
To fix CVE-2025-4275, it is essential to apply the latest firmware updates provided by Insyde that mitigate this vulnerability.
What systems are affected by CVE-2025-4275?
CVE-2025-4275 affects systems running Insyde BIOS, where an attacker could exploit the vulnerability to modify certificates.
Can CVE-2025-4275 allow malware installation?
Yes, CVE-2025-4275 allows attackers to change the certificate, enabling the installation of bootkit malware on compromised systems.
Is there a known exploit for CVE-2025-4275?
Yes, there are known exploits for CVE-2025-4275 that can be used to launch malicious .efi files after manipulating the BIOS certificate.