CVE-2025-33045
APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure of Sensitive Information to an Unauthorized Actor” through local access. The successful exploitation of these vulnerabilities can lead to information disclosure, arbitrary data writing, and impact Confidentiality, Integrity, and Availability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.16%
- CWE
- CWE-123, CWE-200
- Published
- 2025-09-09
- Last modified
- 2026-03-13
Affected products
- AMI AptioV
Weakness type
Related vulnerabilities
- CVE-2026-81579 — An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileged user on Windows
- CVE-2026-20469 — In trusted_mem, there is a possible escalation of privilege due to improper input validation. This...
- CVE-2026-47473 — NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where...
- CVE-2026-45257 — Arbitrary file overwrite via the KTLS receive path
- CVE-2026-41952 — Local privilege escalation due to improper input validation. The following products are affected:...
- CVE-2025-14857 — Semtech LR11xx Memory Write Access Control Bypass
- CVE-2026-25634 — iccDEV memcpy-param-overlap in CIccTagMultiProcessElement::Apply()
- CVE-2025-29943 — Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the...