CVE 7.5 HIGH

UsbCoreDxe: improper input validation may lead to arbitrary code execution_CVE-2025-4276

7.5 / 10
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.

Basic Information

ID CVE-2025-4276
Source Insyde
Published Aug 13, 2025 at 01:41
Modified Aug 14, 2025 at 05:54

Affected Product

Vendor Insyde Software
Product InsydeH2O
Version Kernel 5.3
Affected Versions Insyde Software InsydeH2O Kernel 5.3
Insyde Software InsydeH2O Kernel 5.4
Insyde Software InsydeH2O Kernel 5.5
Insyde Software InsydeH2O Kernel 5.6
Insyde Software InsydeH2O Kernel 5.7

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.