Back to Database
Status published
High
CVE-2025-12051
H2OFFT64.sys is potentially vulnerable to a buffer overflow.
Vulnerability Description
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12051
Credits & Attribution
No credits recorded in the NVD database.
More from Insyde Software
View All →CVE-2025-4426
SetupAutomationSmm : SMRAM memory contents leak / information disclosure vulnerability in SMM module
Medium
6
CVE-2025-4425
SetupAutomationSmm: Stack overflow vulnerability in SMI handler
High
8.2
CVE-2025-4424
SetupAutomationSmm : Arbitrary calls to SmmSetVariable with unsanitised arguments in SMI handler
Medium
6
CVE-2025-4423
SetupAutomationSmm:Vulnerability in the SMM module allow attacker to write arbitrary code and lead to memory corruption
High
8.2
CVE-2025-4422
EfiSmiServices : EfiPcdProtocol, SMM memory corruption vulnerabilities in SMM module
High
8.2
Affected Vendor
Insyde Software
View all reports →Affected Software
InsydeH2O tools
Vulnerable Versions:
See in the Solution
Timeline
Official Publish:
January 14th, 2026
Last Modified:
January 14th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H