CVE-2025-4423 is a high-severity vulnerability (CVSS 8.2) identified in Lenovo-specific code, likely related to UEFI firmware based on media coverage, though specific affected products are not detailed. This vulnerability, categorized as CWE-119, allows a highly privileged attacker (PR:H) to achieve high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) through a locally exploitable attack vector (AV:L/AC:L). While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), it has garnered some community discussion and media attention, suggesting awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Insyde Software | InsydeH2O | >= Feature developed for Lenovo, < L05.05.40.011803.172079CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.