CVE-2025-1125 is a critical vulnerability affecting GNU GRUB2, specifically within its HFS filesystem module. It stems from improper integer overflow checks when calculating buffer sizes from user-controlled HFS filesystem metadata, leading to heap buffer overflows. This flaw can result in arbitrary code execution, potentially bypassing Secure Boot protections. The vulnerability carries a CVSS score of 7.8 (High), indicating a local attack vector with low complexity, requiring user interaction (e.g., booting from a malicious HFS filesystem). Successful exploitation could lead to high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While community discussion is limited, the vulnerability has garnered media attention, notably from BleepingComputer, highlighting Microsoft's use of AI in its discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.12CPE matchmatch criteria | cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.