CVE-2025-12053
- EPSS 0.02%
- Veröffentlicht 14.01.2026 01:27:11
- Zuletzt bearbeitet 14.01.2026 16:25:12
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
CVE-2025-12052
- EPSS 0.02%
- Veröffentlicht 14.01.2026 01:23:54
- Zuletzt bearbeitet 14.01.2026 16:25:12
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
CVE-2025-12051
- EPSS 0.02%
- Veröffentlicht 14.01.2026 01:17:54
- Zuletzt bearbeitet 14.01.2026 16:25:12
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
CVE-2025-12050
- EPSS 0.02%
- Veröffentlicht 14.01.2026 01:15:49
- Zuletzt bearbeitet 14.01.2026 16:25:12
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
CVE-2025-4410
- EPSS 0.02%
- Veröffentlicht 13.08.2025 01:49:47
- Zuletzt bearbeitet 13.08.2025 17:33:46
A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by executeing arbitrary code.
CVE-2025-4277
- EPSS 0.02%
- Veröffentlicht 13.08.2025 01:46:22
- Zuletzt bearbeitet 13.08.2025 17:33:46
Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.
CVE-2025-4276
- EPSS 0.02%
- Veröffentlicht 13.08.2025 01:41:56
- Zuletzt bearbeitet 13.08.2025 17:33:46
UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.
CVE-2025-4422
- EPSS 0.02%
- Veröffentlicht 30.07.2025 01:15:25
- Zuletzt bearbeitet 31.07.2025 18:42:37
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability. https://support.lenovo.com/us/en/product_securi...
CVE-2025-4425
- EPSS 0.02%
- Veröffentlicht 30.07.2025 01:15:25
- Zuletzt bearbeitet 31.07.2025 18:42:37
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability. https://support.lenovo.com/us/en/product_securi...
- EPSS 0.02%
- Veröffentlicht 30.07.2025 01:15:25
- Zuletzt bearbeitet 31.07.2025 18:42:37
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability. https://support.lenovo.com/us/en/product_securi...