PT-2025-20696 · Microsoft · Uefi +1

Published

2025-05-12

·

Updated

2025-09-29

·

CVE-2025-3052

CVSS v3.1
8.2
VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description A security issue has been identified in a UEFI module signed by Microsoft. The problem is related to repeatable supply chain security failures in firmware key management. There is no information available about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-06727
CVE-2025-3052

Affected Products

Uefi
Windows