CVE-2025-3052: An arbitrary write vulnerability in Microsoft signed UEFI firmware from DT Research Inc.
An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.
Other sources
Cert CC: CVE-2025-3052 InsydeH2O Secure Boot Bypass
— Microsoft
Untrusted pointer dereference in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3052?
CVE-2025-3052 has a high severity rating due to its potential for local code execution by an authenticated attacker.
How do I fix CVE-2025-3052?
To fix CVE-2025-3052, apply the appropriate security patches provided by Microsoft for the affected Windows versions.
What systems are affected by CVE-2025-3052?
CVE-2025-3052 affects various Windows 10 and Windows 11 versions, as well as Windows Server editions.
What type of attack does CVE-2025-3052 enable?
CVE-2025-3052 enables an attacker to perform arbitrary code execution on affected systems, potentially bypassing Secure Boot.
Is there a workaround for CVE-2025-3052?
Currently, there is no known workaround for CVE-2025-3052; updating to the latest patches is recommended.