« Volver al listado

CVE-2025-7026

Estado: AplazadaAlta (8.2)—

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer in the CommandRcx0 function. If the contents at RBX match certain expected values (e.g., '$DB$' or '2DB$'), the function performs arbitrary writes to System Management RAM (SMRAM), leading to potential privilege escalation to System Management Mode (SMM) and persistent firmware compromise.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local (AV:L) sin interacción (UI:N) con privilegios altos (PR:H) permite escalar a SMM mediante escritura arbitraria en SMRAM, comprometiendo el firmware de forma persistente.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-7026",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-7026",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-12T03:55:16.064357Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.5
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "GIGABYTE",
          "product": "UEFI-GenericComponentSmmEntry",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-07-11T16:15:26.897",
  "references": [
    {
      "url": "https://kb.cert.org/vuls/id/746790",
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.binarly.io/advisories/brly-dva-2025-008",
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.gigabyte.com/Support/Security",
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/746790",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer in the CommandRcx0 function. If the contents at RBX match certain expected values (e.g., '$DB$' or '2DB$'), the function performs arbitrary writes to System Management RAM (SMRAM), leading to potential privilege escalation to System Management Mode (SMM) and persistent firmware compromise."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en el controlador Software SMI (SwSmiInputValue 0xB2) permite a un atacante local controlar el registro RBX, que se utiliza como puntero sin control en la función CommandRcx0. Si el contenido de RBX coincide con ciertos valores esperados (p. ej., '$DB$' o '2DB$'), la función realiza escrituras arbitrarias en la RAM de administración del sistema (SMRAM), lo que puede provocar una escalada de privilegios al modo de administración del sistema (SMM) y una vulnerabilidad persistente del firmware."
    }
  ],
  "lastModified": "2026-06-17T10:04:07.337",
  "sourceIdentifier": "cret@cert.org"
}