A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-06-11 01:15
Updated : 2026-06-17 09:32
NVD link : CVE-2025-4275
Mitre link : CVE-2025-4275
CVE.ORG link : CVE-2025-4275
JSON object : View
Products Affected
No product.
CWE
No CWE.
