PT-2025-20696 · Microsoft · Uefi+1

Published

2025-05-12

·

Updated

2026-05-13

·

CVE-2025-3052

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft signed UEFI firmware (affected versions not specified)
Description An arbitrary write vulnerability exists in Microsoft-signed UEFI firmware due to the unsafe handling of the IhisiParamBuffer NVRAM variable. The firmware reads the content of this variable and uses it as a pointer for memory write operations without proper validation. This allows a privileged attacker to control the value and perform arbitrary memory writes, such as overwriting the gSecurity2 global variable to disable Secure Boot enforcement during the boot process. Consequently, this can lead to the execution of untrusted software, the installation of bootkits that remain invisible to the operating system, security bypasses, persistence mechanisms, or full system compromise. The issue affects 14 modules signed with the "Microsoft Corporation UEFI CA 2011" certificate. Insyde-based devices are protected due to variable locking, but most other UEFI systems are vulnerable.
Recommendations Update the Secure Boot dbx immediately. Monitor NVRAM variable modifications. Hunt for unexpected UEFI modules in the Boot Manager. As a temporary workaround, restrict access to the IhisiParamBuffer NVRAM variable to minimize the risk of exploitation.

Fix

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-06727
CVE-2025-3052

Affected Products

Uefi
Windows