CVE 8.4 HIGH

Un-verified kernel bypass Secure Boot mechanism in direct boot mode_CVE-2025-2296

8.4 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L

Description

EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.

Basic Information

ID CVE-2025-2296
Source TianoCore
Published Dec 9, 2025 at 15:00
Modified Dec 9, 2025 at 15:11

Affected Product

Vendor TianoCore
Product EDK2
Affected Versions TianoCore EDK2 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.