Home

Description

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer in the CommandRcx0 function. If the contents at RBX match certain expected values (e.g., '$DB$' or '2DB$'), the function performs arbitrary writes to System Management RAM (SMRAM), leading to potential privilege escalation to System Management Mode (SMM) and persistent firmware compromise.

PUBLISHED Reserved 2025-07-02 | Published 2025-07-11 | Updated 2026-02-26 | Assigner certcc

Problem types

CWE-822 Untrusted Pointer Dereference

Product status

1.0.0
affected

References

www.kb.cert.org/vuls/id/746790

www.gigabyte.com/Support/Security

www.binarly.io/advisories/brly-dva-2025-008

kb.cert.org/vuls/id/746790

cve.org (CVE-2025-7026)

nvd.nist.gov (CVE-2025-7026)

Download JSON