PT-2025-20696 · Microsoft · Uefi+1
Published
2025-05-12
·
Updated
2026-05-13
·
CVE-2025-3052
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft signed UEFI firmware (affected versions not specified)
Description
An arbitrary write vulnerability exists in Microsoft-signed UEFI firmware due to the unsafe handling of the
IhisiParamBuffer NVRAM variable. The firmware reads the content of this variable and uses it as a pointer for memory write operations without proper validation. This allows a privileged attacker to control the value and perform arbitrary memory writes, such as overwriting the gSecurity2 global variable to disable Secure Boot enforcement during the boot process. Consequently, this can lead to the execution of untrusted software, the installation of bootkits that remain invisible to the operating system, security bypasses, persistence mechanisms, or full system compromise. The issue affects 14 modules signed with the "Microsoft Corporation UEFI CA 2011" certificate. Insyde-based devices are protected due to variable locking, but most other UEFI systems are vulnerable.Recommendations
Update the Secure Boot dbx immediately.
Monitor NVRAM variable modifications.
Hunt for unexpected UEFI modules in the Boot Manager.
As a temporary workaround, restrict access to the
IhisiParamBuffer NVRAM variable to minimize the risk of exploitation.Fix
Untrusted Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uefi
Windows