CVE-2025-12050
UEFI Firmware: Out-of-bounds Write (CVE-2025-12050)
highEPSS 0.2%
Affected
- Insyde/UEFI Firmware
= InsydeH2O..InsydeH2O
Description
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
Source: BSI CSAFBSI WID Portalcvelistv5
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
InsydeUEFI Firmware
InsydeH2OMetrics
Show all metrics
Severity
high
53.28
no public PoC known
7.8
Published
2026-01-14 01:13 UTC
CWE-787
Weakness classes (CWE)
CWE-787Base
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
cwe.mitre.org →