CVE-2025-4275: Insyde Software INSYDEH2O

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.

Affected products

Published 2025-06-11. Last modified 2026-06-17.