CVE-2025-12053 describes a high-severity buffer overflow vulnerability (CVSS 7.8) in unspecified drivers within tool packages. This flaw allows an untrusted user-mode application to trigger a buffer overflow by leveraging the RTL_QUERY_REGISTRY_DIRECT flag when reading a registry value. Successful exploitation could lead to high confidentiality, integrity, and availability impacts. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Insyde Software | InsydeH2O Tools | See in the SolutionCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.