CVE-2025-2295: Tianocore EDK2

Low severity, CVSS 3.5. EPSS: 0.2% chance of exploitation in the next 30 days.

EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.

Affected products

Published 2025-03-14. Last modified 2026-06-17.