Buffer Overflow Vulnerability in Insyde Tool Package Drivers
CVE-2025-12051
7.8HIGH
What is CVE-2025-12051?
The Insyde tool packages contain a vulnerability in their drivers due to the use of the RTL_QUERY_REGISTRY_DIRECT flag. This flaw allows an untrusted user-mode application to potentially exploit the system by causing a buffer overflow when attempting to read certain registry values. This could lead to application crashes or the execution of malicious code, emphasizing the need for immediate updates and patches to secure affected installations.
Affected Version(s)
InsydeH2O tools Windows See in the Solution
