CVE-2025-3052 Information
Jun 11, 2025
cve
Description
An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value leading to arbitrary memory writes including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses persistence mechanisms or full system compromise.
Reference
https://uefi.org/specs/UEFI/2.10/32_Secure_Boot_and_Driver_Signing.html https://www.binarly.io/advisories/brly-dva-2025-001 https://www.kb.cert.org/vuls/id/806555
Share on: