SB2025061060 - Privilege escalation in Insyde H2O UEFI



SB2025061060 - Privilege escalation in Insyde H2O UEFI

Published: June 10, 2025

Security Bulletin ID SB2025061060
Severity
Low
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Exposed dangerous method or function (CVE-ID: CVE-2025-4275)

The vulnerability allows an attacker to escalate privileges on the system.

The vulnerability exists due to usage of an unprotected NVRAM variable. An attacker with physical access to the system can inject their own certificate in this variable and subsequently run arbitrary firmware (signed by the injected certificate) during the early boot process within the UEFI environment.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.