CVE 7.5 HIGH

Tcg2Smm: improper input validation may lead to arbitrary code execution_CVE-2025-4277

7.5 / 10
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.

Basic Information

ID CVE-2025-4277
Source Insyde
Published Aug 13, 2025 at 01:46
Modified Aug 14, 2025 at 05:54

Affected Product

Vendor Insyde Software
Product InsydeH2O
Version Kernel 5.2
Affected Versions Insyde Software InsydeH2O Kernel 5.2
Insyde Software InsydeH2O Kernel 5.3
Insyde Software InsydeH2O Kernel 5.4
Insyde Software InsydeH2O Kernel 5.5
Insyde Software InsydeH2O Kernel 5.6
Insyde Software InsydeH2O Kernel 5.7

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.