PT-2025-29262 · Unknown · Software Smi Handler

Published

2025-04-15

·

Updated

2025-07-18

·

CVE-2025-7028

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Software SMI Handler (affected versions not specified)
Description A vulnerability in the Software SMI handler (SwSmiInputValue 0x20) allows a local attacker to supply a crafted pointer (FuncBlock) through RBX and RCX register values. This pointer is passed unchecked into multiple flash management functions (ReadFlash, WriteFlash, EraseFlash, and GetFlashInfo) that dereference both the structure and its nested members, such as BufAddr. This enables arbitrary read/write access to System Management RAM (SMRAM), allowing an attacker to corrupt firmware memory, exfiltrate SMRAM content via flash, or install persistent implants.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-09302
CVE-2025-7028

Affected Products

Software Smi Handler