SB2025061304 - Dell Client Platform update for INSYDE BIOS
Published: June 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Exposed dangerous method or function (CVE-ID: CVE-2025-4275)
The vulnerability allows an attacker to escalate privileges on the system.
The vulnerability exists due to usage of an unprotected NVRAM variable. An attacker with physical access to the system can inject their own certificate in this variable and subsequently run arbitrary firmware (signed by the injected certificate) during the early boot process within the UEFI environment.
Remediation
Install update from vendor's website.