CVE-2025-12051: Insyde Software INSYDEH2O Tools

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.

Affected products

Published 2026-01-14. Last modified 2026-06-17.