CVE-2025-4275: Insyde Software INSYDEH2O
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.
Affected products
- Insyde Software INSYDEH2O
Published 2025-06-11. Last modified 2026-06-17.