CVE-2025-3770

Published Aug 7, 2025

Last updated 2 months ago

Overview

Description
EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.
Source
infosec@edk2.groups.io
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
7
Impact score
5.9
Exploitability score
1
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

infosec@edk2.groups.io
CWE-693

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.