CVE-2025-4422 is a high-severity vulnerability (CVSS 8.2) found in Lenovo-specific code, likely affecting their products, though specific affected models are not yet detailed. This vulnerability, categorized as CWE-787 (Out-of-bounds Write), could allow a highly privileged local attacker to achieve significant impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including a BleepingComputer article mentioning Lenovo UEFI firmware updates fixing Secure Boot bypass flaws.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Insyde Software | InsydeH2O | >= Feature developed for Lenovo, < L05.05.40.011803.172079CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.