CVE-2025-4275
EUVD-2025-1807011.06.2025, 01:15
A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| insyde | insydeh2o | 𝑥 < 5.2A.16 | CNA |
| insyde | insydeh2o | 𝑥 < 5.39.16 | CNA |
| insyde | insydeh2o | 𝑥 < 5.47.16 | CNA |
| insyde | insydeh2o | 𝑥 < 5.55.16 | CNA |
| insyde | insydeh2o | 𝑥 < 5.62.16 | CNA |
| insyde | insydeh2o | 𝑥 < 5.71.16 | CNA |