An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-17820 An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00016}

epss

{'score': 0.00017}


Thu, 12 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 10 Jun 2025 21:30:00 +0000

Type Values Removed Values Added
References

Tue, 10 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 19:30:00 +0000

Type Values Removed Values Added
Description An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.
Title An arbitrary write vulnerability in Microsoft signed UEFI firmware from DT Research Inc.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2025-06-10T21:03:04.250Z

Reserved: 2025-03-31T16:26:00.858Z

Link: CVE-2025-3052

cve-icon Vulnrichment

Updated: 2025-06-10T21:03:04.250Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-10T20:15:23.037

Modified: 2025-06-12T16:06:29.520

Link: CVE-2025-3052

cve-icon Redhat

Severity : Important

Publid Date: 2025-06-11T14:40:00Z

Links: CVE-2025-3052 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.