CVE-2025-3770 – EDK2 BIOS Bootkit Execution

The following table lists the changes that have been made to the
CVE-2025-3770 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 07, 2025

    Action Type Old Value New Value
    Added Description EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.
    Added CVSS V3.1 AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-693
    Added Reference https://github.com/tianocore/edk2/security/advisories/GHSA-vx5v-4gg6-6qxr
Share the Post:

Related Posts