CVE-2025-12053

UEFI Firmware: Out-of-bounds Write (CVE-2025-12053)

Affected

  • Insyde/UEFI Firmware = InsydeH2O..InsydeH2O

Description

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

InsydeUEFI Firmware
InsydeH2O

Metrics

7.8
Source: cna-v3
5.0 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-01-14 01:27 UTC
CWE-787

Weakness classes (CWE)

  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

References & sources