7.8
CVSSv3

CVE-2025-4275

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: NA | VMScore: 880 | EPSS: 9.0E-5 | KEV: Not Included
Published: 11/06/2025 Updated: 12/06/2025

Vulnerability Summary

Insyde BIOS Certificate Manipulation Enabling Arbitrary EFI File Launch

Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched.

Solution

kernel 5.2, Version 05.2A.16
kernel 5.3, Version 05.39.16
kernel 5.4, Version 05.47.16
kernel 5.5, Version 05.55.16
kernel 5.6, Version 05.62.16
kernel 5.7, Version 05.71.16

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

insyde software insydeh2o

Recent Articles

New Secure Boot flaw lets attackers install bootkit malware, patch now
BleepingComputer • Lawrence Abrams • 10 Jun 2025

New Secure Boot flaw lets attackers install bootkit malware, patch now By Lawrence Abrams June 10, 2025 04:02 PM 0 Security researchers have disclosed a new Secure Boot bypass tracked as CVE-2025-3052 that can be used to turn off security on PCs and servers and install bootkit malware. The flaw affects nearly every system that trusts Microsoft's "UEFI CA 2011" certificate, which is pretty much all hardware that supports Secure Boot. Binarly researcher Alex Matrosov discovered the CVE-2025-3052 f...