CVE-2025-3052 Information

Description

An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value leading to arbitrary memory writes including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses persistence mechanisms or full system compromise.

Reference

https://uefi.org/specs/UEFI/2.10/32_Secure_Boot_and_Driver_Signing.html https://www.binarly.io/advisories/brly-dva-2025-001 https://www.kb.cert.org/vuls/id/806555

Share on: