ZDI-25-884: QEMU uefi-vars Uninitialized Memory Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of QEMU. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2025-8860.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-884?
ZDI-25-884 has a CVSS score indicating a high severity level, reflecting its potential impact on sensitive information disclosure.
How do I fix ZDI-25-884?
To mitigate ZDI-25-884, ensure that you are running the latest patched version of QEMU provided by the vendor.
What type of attacks can be executed with ZDI-25-884?
ZDI-25-884 allows local attackers to exploit the vulnerability for sensitive information disclosure on affected installations of QEMU.
What is required to exploit ZDI-25-884?
An attacker must first obtain the ability to execute high-privileged code on the target guest system to exploit ZDI-25-884.
Who is affected by ZDI-25-884?
All installations of QEMU that have not been patched against ZDI-25-884 are vulnerable to this information disclosure issue.