VYPR

UEFI

by Gigabyte

CVEs (1)

  • CVE-2025-7027HigJul 11, 2025
    risk 0.53cvss 8.2epss 0.00

    A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control both the read and write addresses used by the CommandRcx1 function. The write target is derived from an unvalidated UEFI NVRAM variable (SetupXtuBufferAddress), while the write…