Arbitrary Memory Write Vulnerability in Gigabyte Firmware
CVE-2025-7027

8.2HIGH

Key Information:

Vendor

Gigabyte

Vendor
CVE Published:
11 July 2025

What is CVE-2025-7027?

A vulnerability exists in the Software SMI handler that allows a local attacker to manipulate read and write addresses via the CommandRcx1 function. This vulnerability arises from an unvalidated UEFI NVRAM variable, leading to potential arbitrary memory writes within System Management RAM (SMRAM). By leveraging an attacker-controlled pointer and exploiting dual-pointer dereference, this flaw can facilitate SMM privilege escalation and compromise of the firmware, posing significant security risks.

Affected Version(s)

UEFI-GenericComponentSmmEntry 1.0.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7027 : Arbitrary Memory Write Vulnerability in Gigabyte Firmware