SB2025061304 - Dell Client Platform update for INSYDE BIOS



SB2025061304 - Dell Client Platform update for INSYDE BIOS

Published: June 13, 2025

Security Bulletin ID SB2025061304
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Exposed dangerous method or function (CVE-ID: CVE-2025-4275)

The vulnerability allows an attacker to escalate privileges on the system.

The vulnerability exists due to usage of an unprotected NVRAM variable. An attacker with physical access to the system can inject their own certificate in this variable and subsequently run arbitrary firmware (signed by the injected certificate) during the early boot process within the UEFI environment.


Remediation

Install update from vendor's website.