CVE-2025-10451
Unknown Unknown - Not Provided
Unchecked Buffer Overflow in SMM Allows Arbitrary Code Execution

Publication date: 2025-12-12

Last updated on: 2025-12-12

Assigner: Insyde

Description
Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-12
Last Modified
2025-12-12
Generated
2026-06-16
AI Q&A
2025-12-12
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 5 associated CPEs
Vendor Product Version / Range
intel kaby_lake *
insyde insydeh2o *
amd picasso *
intel ice_lake *
hp feature *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves an unchecked output buffer that may allow arbitrary code execution within the System Management Mode (SMM). This can potentially lead to corruption of the SMM memory.

Mitigation Strategies

Apply the patch IB05690966 released for HP feature versions before 20C1, which addresses the vulnerability in platforms based on Intel Ice Lake, Kaby Lake, and AMD Picasso processors. This patch mitigates the unchecked output buffer issue in the InsydeH2O firmware's SMM phase to prevent arbitrary code execution and memory corruption. [1]

Impact Analysis

The vulnerability can lead to arbitrary code execution and memory corruption in SMM, which may compromise system security, potentially allowing attackers to gain high-privilege control and cause significant system damage or data loss.

Compliance Impact

The provided resources do not contain information regarding the impact of this vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-10451. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart