EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 07 Aug 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tianocore
Tianocore edk2 |
|
| Vendors & Products |
Tianocore
Tianocore edk2 |
Thu, 07 Aug 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability. | |
| Title | SMM IDT Privilege Escalation Vulnerability | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TianoCore
Published: 2025-08-07T00:42:14.628Z
Updated: 2025-08-07T13:28:12.175Z
Reserved: 2025-04-17T16:10:59.678Z
Link: CVE-2025-3770
Updated: 2025-08-07T13:28:09.458Z
Status : Awaiting Analysis
Published: 2025-08-07T01:15:25.713
Modified: 2025-08-07T21:26:37.453
Link: CVE-2025-3770