{"id":"CVE-2025-2296","title":"EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access","summary":"EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary com…","severity":"none","cwe":["CWE-20"],"published":"2025-12-09","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-2296","references":[{"url":"https://github.com/tianocore/edk2/security/advisories/GHSA-6pp6-cm5h-86g5","label":"infosec@edk2.groups.io"}],"tags":["nvd"],"epss":0.00772,"epssPercentile":0.54206,"ingestedAt":"2026-10-07T20:46:46.789Z","slug":"CVE-2025-2296","body":"## Overview\n\nEDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}