Vulnerability Description
A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.
CVSS Score
HIGH
References
FAQ
What is CVE-2025-4275?
CVE-2025-4275 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated N...
How severe is CVE-2025-4275?
CVE-2025-4275 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-4275?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.