CVE-2025-3770 Details
Description
EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.
A vulnerability exists in the EDK2 BIOS implementation, where local access can lead to a 'Protection Mechanism Failure'. This flaw allows an attacker to execute arbitrary code, potentially causing significant harm by compromising the system's confidentiality, integrity, and availability.
Users can apply the available patch included in the advisory to address this vulnerability. The patch modifies the X64/SmiEntry.nasm file to change the order of operations related to Machine Check Exceptions and the Interrupt Descriptor Table, ensuring that the IDT is properly configured before enabling MCEs in SMM.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2025CISA-ADP
Assessed Aug 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/tianocore/edk2/security/advisories/GHSA-vx5v-4gg6-6qxr | [email protected] | AdvisoryRemedySource CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| EDK2 | <= 202508 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2025 | New CVE Received | [email protected] |
Volerion