vulnerability

Ubuntu: USN-7894-1 (CVE-2025-3770): EDK II vulnerabilities

Severity
7
CVSS
(AV:L/AC:M/Au:S/C:C/I:C/A:C)
Published
Aug 7, 2025
Added
Oct 30, 2025
Modified
Nov 28, 2025

Description

EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.

Solutions

ubuntu-upgrade-ovmfubuntu-upgrade-ovmf-ia32ubuntu-upgrade-qemu-efiubuntu-upgrade-qemu-efi-aarch64ubuntu-upgrade-qemu-efi-armubuntu-upgrade-qemu-efi-loongarch64ubuntu-upgrade-qemu-efi-riscv64
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.