CVE-2025-12050
UEFI Firmware: Out-of-bounds Write (CVE-2025-12050)
Affected
- Insyde/UEFI Firmware
= InsydeH2O..InsydeH2O
Description
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
Source: BSI
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
InsydeH2OMetrics
Show all metrics
Weakness classes (CWE)
CWE-787Base
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
cwe.mitre.org →
References & sources
Linked CVEs
- CVE-2025-12053
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application…
highCVSSv3 7.8 - CVE-2025-12052
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application…
highCVSSv3 7.8 - CVE-2025-12051
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application…
highCVSSv3 7.8 - CVE-2025-12050
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application…
highCVSSv3 7.8