CVE-2025-12052 Details
Description
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
A buffer overflow vulnerability has been identified in the InsydeH2O driver 'egwindrv.sys'. This vulnerability arises because the driver uses the RTL_QUERY_REGISTRY_DIRECT flag to read a registry value, which an untrusted user-mode application may exploit to cause a buffer overflow.
Users are advised to update to version 200.02.01.00 or newer. For those using HP tools, versions 6.51.00, 1.2.4.0, 6.2.5.0, and 1.2.0.2 are recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 14, 2026CISA-ADP
Assessed Jan 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.insyde.com/security-pledge/sa-2025010/ | Insyde | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | Insyde |
Affected Products
| Product | Versions |
|---|---|
| InsydeH2O | < 6.76.00 (semver) < 200.02.01.00 |
CPE
Remediation
| |
| InsydeH2OFFT | < 6.76.00 (semver) < 200.02.01.00 |
CPE
Remediation
| |
| InsydeH2OUVE | < 200.02.01.00 |
CPE
Remediation
| |
| InsydeH2OSDE | < 200.02.01.00 |
CPE
Remediation
| |
| InsydeH2ORTE | < 200.02.01.00 |
CPE
Remediation
| |
| InsydeH2OOAE | < 200.02.01.00 |
CPE
Remediation
| |
| InsydeH2OPCM | < 200.02.01.00 |
CPE
Remediation
| |
| InsydeH2OELV | < 200.02.01.00 |
CPE
Remediation
| |
| InsydeH2OUVE_ARM | All versions |
CPE
Remediation
| |
| InsydeH2OSDE_ARM | All versions |
CPE
Remediation
| |
| InsydeH2ORTE_ARM | All versions |
CPE
Remediation
| |
| HP FlashWin | All versions |
CPE
Remediation
| |
| HP Readback tool | All versions |
CPE
Remediation
| |
| HP FlashVerifyUtility | All versions |
CPE
Remediation
| |
| HP IsSecureBootKeyInstaller | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Insyde |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | New CVE Received | Insyde |
Volerion