Loading HuntDB...

GHSA-q4rv-v64c-3hff

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.

Related CVEs

Key Information

GHSA ID
GHSA-q4rv-v64c-3hff
Published
June 10, 2025 9:31 PM
Last Modified
June 10, 2025 9:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.