CVE-2025-2296EPSS p54.4%
CVE-2025-2296CVE-2025-2296
Description
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.
Scoring
| EPSS | 0.77% probability of exploitation · percentile 54.4% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |