CVE-2025-4275

A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.
Configurations

No configuration.

History

No history.

Information

Published : 2025-06-11 01:15

Updated : 2026-06-17 09:32


NVD link : CVE-2025-4275

Mitre link : CVE-2025-4275

CVE.ORG link : CVE-2025-4275


JSON object : View

Products Affected

No product.

CWE

No CWE.