CVE-2025-3052 Details
Description
An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.
A vulnerability in Microsoft-signed UEFI firmware allows for arbitrary memory writes, enabling code execution of untrusted software and bypassing Secure Boot. This vulnerability affects several UEFI applications, including 'DTBios' and 'BiosFlashShell', all signed by the 'Microsoft Corporation UEFI CA 2011' key. The issue arises from improper handling of a runtime NVRAM variable, 'IhisiParamBuffer', which can be manipulated to overwrite critical firmware settings, such as those governing Secure Boot. Exploitation of this vulnerability could lead to the execution of malicious UEFI bootkits before the operating system is fully loaded, compromising system integrity and evading detection by conventional security measures.
To address this vulnerability, the affected UEFI applications must be updated to remove the vulnerable code. Additionally, the 'Dtbios-efi64-71.22.efi' module should be added to the UEFI Forbidden Signature Database (DBX) to prevent its execution under Secure Boot. This vulnerability has been found in multiple versions of the 'DTBios' application, so all variations should be added to the DBX database.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 10, 2025CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/806555 | CVE | AdvisoryBundleRemedy |
| https://uefi.org/specs/UEFI/2.10/32_Secure_Boot_and_Driver_Signing.html | [email protected] | |
| https://www.binarly.io/advisories/brly-dva-2025-001 | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Microsoft UEFI | All versions |
CPE
Remediation
| |
| DT Research Dtbios | All versions |
CPE
Remediation
| |
| DT Research BiosFlashShell | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2025 | CVE Modified | CVE |
| Jun 10, 2025 | New CVE Received | [email protected] |
| Jun 10, 2025 | CVE Modified | CISA-ADP |
Volerion