Sploitus

CVE-2025-7028

1 known exploit for CVE-2025-7028

A vulnerability in the Software SMI handler (SwSmiInputValue 0x20) allows a local attacker to supply a crafted pointer (FuncBlock) through RBX and RCX register values. This pointer is passed unchecked into multiple flash management functions (ReadFlash, WriteFlash, EraseFlash, and GetFlashInfo) that dereference both the structure and its nested members, such as BufAddr. This enables arbitrary read/write access to System Management RAM (SMRAM), allowing an attacker to corrupt firmware memory, exfiltrate SMRAM content via flash, or install persistent implants.

Affected products
Software Smi Handler
CVSS 3.1
7.8 HIGH
EPSS
0.2% (9th percentile)
NVD status
Deferred
Published
2025-07-11
CVE-2025-7028 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-7028

Proof-of-concept code and exploit modules indexed by Sploitus