Back to Database
Status published
High
CVE-2025-10451
H19Int15CallbackSmm: SMM memory corruption vulnerability in combined DXE/SMM (SMRAM write)
Vulnerability Description
Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10451
Credits & Attribution
No credits recorded in the NVD database.
More from Insyde Software
View All →CVE-2025-4426
SetupAutomationSmm : SMRAM memory contents leak / information disclosure vulnerability in SMM module
Medium
6
CVE-2025-4425
SetupAutomationSmm: Stack overflow vulnerability in SMI handler
High
8.2
CVE-2025-4424
SetupAutomationSmm : Arbitrary calls to SmmSetVariable with unsanitised arguments in SMI handler
Medium
6
CVE-2025-4423
SetupAutomationSmm:Vulnerability in the SMM module allow attacker to write arbitrary code and lead to memory corruption
High
8.2
CVE-2025-4422
EfiSmiServices : EfiPcdProtocol, SMM memory corruption vulnerabilities in SMM module
High
8.2
Affected Vendor
Insyde Software
View all reports →Affected Software
InsydeH2O
Vulnerable Versions:
HP feature version before 20C1
Timeline
Official Publish:
December 12th, 2025
Last Modified:
December 12th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H