CVE-2025-3052
HIGHDT Research BiosFlashShell 80.02 and Dtbios 70.17-70.22/71.17-71.22 - Arbitrary Memory Write via UEFI Firmware
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-3052. PoCs published by TheMalwareGuardian.
AI-analyzed exploit summary This repository provides a detailed technical reproduction of CVE-2025-3052, a UEFI Secure Boot bypass vulnerability in DT Research firmware. The PoC includes vulnerable binary emulation, exploitation explanation, and NVRAM variable manipulation to achieve arbitrary memory writes via the IhisiParamBuffer NVRAM variable.
Description
An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.
Exploits (1)
This repository provides a detailed technical reproduction of CVE-2025-3052, a UEFI Secure Boot bypass vulnerability in DT Research firmware. The PoC includes vulnerable binary emulation, exploitation explanation, and NVRAM variable manipulation to achieve arbitrary memory writes via the IhisiParamBuffer NVRAM variable.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H