Vulnerability Description
A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer in the CommandRcx0 function. If the contents at RBX match certain expected values (e.g., '$DB$' or '2DB$'), the function performs arbitrary writes to System Management RAM (SMRAM), leading to potential privilege escalation to System Management Mode (SMM) and persistent firmware compromise.
CVSS Score
HIGH
References
- https://kb.cert.org/vuls/id/746790
- https://www.binarly.io/advisories/brly-dva-2025-008
- https://www.gigabyte.com/Support/Security
- https://www.kb.cert.org/vuls/id/746790
FAQ
What is CVE-2025-7026?
CVE-2025-7026 is a vulnerability with a CVSS score of 8.2 (HIGH). A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer in the CommandRcx0 function. If the conten...
How severe is CVE-2025-7026?
CVE-2025-7026 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-7026?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.