CVE-2025-12050

UEFI Firmware: Out-of-bounds Write (CVE-2025-12050)

mediumEPSS 0.2%

Affected

  • Insyde/UEFI Firmware = InsydeH2O..InsydeH2O

Description

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.

Source: BSI

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

InsydeUEFI Firmware
InsydeH2O

Metrics

7.8
Source: cna-v3
6.2 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-28 09:06 UTC
CWE-787

Weakness classes (CWE)

  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

References & sources

Linked CVEs