Back to Database
Status published
High
CVE-2025-4276
UsbCoreDxe: improper input validation may lead to arbitrary code execution
Vulnerability Description
UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4276
Credits & Attribution
No credits recorded in the NVD database.
More from Insyde Software
View All →CVE-2025-4426
SetupAutomationSmm : SMRAM memory contents leak / information disclosure vulnerability in SMM module
Medium
6
CVE-2025-4425
SetupAutomationSmm: Stack overflow vulnerability in SMI handler
High
8.2
CVE-2025-4424
SetupAutomationSmm : Arbitrary calls to SmmSetVariable with unsanitised arguments in SMI handler
Medium
6
CVE-2025-4423
SetupAutomationSmm:Vulnerability in the SMM module allow attacker to write arbitrary code and lead to memory corruption
High
8.2
CVE-2025-4422
EfiSmiServices : EfiPcdProtocol, SMM memory corruption vulnerabilities in SMM module
High
8.2
Affected Vendor
Insyde Software
View all reports →Affected Software
InsydeH2O
Vulnerable Versions:
Kernel 5.3, Kernel 5.4, Kernel 5.5, Kernel 5.6, Kernel 5.7
Timeline
Official Publish:
August 13th, 2025
Last Modified:
August 14th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H