CVE-2025-4276

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
13/08/2025
Last modified:
13/08/2025

Description

UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.

References to Advisories, Solutions, and Tools