CVE-2025-3052Disclosure

HIGHCVSS 8.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.

6.0/ 10 priority

Sources & remediation

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-06); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-06: 1Mentions · 2026-03-18: 1Mentions · 2026-04-10: 1Mentions · 2026-05-13: 1Exploit Tool / Code · 2026-05-13: 1Active Exploitation · 2026-03-18: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-02-06: 1Technical Details · 2026-03-18: 1Technical Details · 2026-05-13: 102-0603-1804-1005-13
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-061
Disclosure1
2026-03-181
Active Exploitation1
2026-04-101
Disclosure1
2026-05-131
Disclosure1
Full discourse4 posts
  • 0xor0ne@0xor0ne
    Disclosure

    CVE-2025-3052 explained: running unsigned code during the UEFI boot process https://www.binarly.io/blog/another-crack-in-the-chain-of-trust Credits @binarly_io #infosec https://t.co/31sZcjuaDf

    Post summary

    The tweet announces CVE‑2025‑3052, noting it allows unsigned code to run during UEFI boot, and links to a blog for further disclosure.

    1360147858.6K
    87.7K followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    Running unsigned code during the UEFI boot process (CVE-2025-3052) https://binarly.io/blog/another-crack-in-the-chain-of-trust Credits @binarly_io #infosec https://t.co/7cs9mJInB6

    Post summary

    The tweet links to a blog post announcing UEFI boot vulnerability CVE‑2025‑3052 but offers no PoC, exploitation evidence, patch advice, or technical details.

    0231107687.4K
    91.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Binarly Research exposes CVE-2025-3052 (BRLY-2025-001): memory corruption in Microsoft-signed UEFI module enables arbitrary memory writes and complete Secure Boot bypass on most UEFI systems. Critical technical details: • Affects 14 modules signed with "Microsoft Corporation UEFI CA 2011" certificate - same cert used for Linux shim bootloader • Root cause: unsafe handling of IhisiParamBuffer NVRAM variable allows arbitrary memory write primitive • Attack overwrites gSecurity2 global variable to disable Secure Boot enforcement during boot process • Originally DT Research BIOS flashing tool (Dtbios-efi64-71.22.efi), signed October 2022, discovered on VirusTotal November 2024 • Insyde-based devices protected due to variable locking, but all other UEFI systems vulnerable Attack methodology: • Privileged attacker sets malicious IhisiParamBuffer value from OS • Registers vulnerable module + unsigned payload module in UEFI Boot Manager • On reboot, vulnerable module executes during BDS phase, overwrites security checks • Unsigned payload executes with Secure Boot appearing enabled to OS Impact enables bootkit installation before OS loads, bypassing all OS-level defenses. Microsoft added 14 hashes to Secure Boot dbx on June 10, 2025 Patch Tuesday. Update Secure Boot dbx immediately. Hunt for unexpected UEFI modules in Boot Manager and monitor NVRAM variable modifications. #DFIR_Radar

    Post summary

    Binarly Research disclosed CVE‑2025‑3052, a memory corruption flaw in Microsoft‑signed UEFI modules that allows complete Secure Boot bypass, and Microsoft has released a patch to address the issue.

    100101.0K
    1.5K followersView on X
  • SQUID SEC@Squid_Sec
    Active Exploitation

    Supply Chain Armageddon 2026: Shai-Hulud worms owning npm, UEFI bootkits persisting below OS (CVE-2025-3052), MSP creds abused cascading to hundreds. Borders gone—your deps/hardware/providers = global attack surface. Why SBOMs fail + real defenses https://squidhacker.com/2026/03/supply-chain-armageddon-now-defending-software-hardware-and-msp-dependencies-in-a-world-without-borders/ Part 2 of Resilience series. Read before the next variant hits. ☣️ #SupplyChainSecurity #CyberSecurity #MSP #Firmware #ZeroTrust

    Post summary

    The post highlights real‑world exploitation of CVE‑2025‑3052 through UEFI bootkits and widespread MSP credential abuse, but it does not provide patch information or a PoC.

    00010146
    199 followersView on X

Explore more