Cyber Security News

Gigabyte UEFI Firmware Vulnerability Let Attackers Execute Arbitrary Code in the SMM Environment

Critical security vulnerabilities have been discovered in Gigabyte UEFI firmware that could allow attackers to execute arbitrary code in System Management Mode (SMM), one of the most privileged execution environments in modern processors. 

The vulnerabilities, disclosed by the Software Engineering Institute’s CERT Coordination Center on July 11, 2025, affect multiple Gigabyte systems and could enable attackers to bypass fundamental security protections, including Secure Boot and Intel BootGuard.

Key Takeaways
1. Four CVE vulnerabilities in Gigabyte UEFI firmware allow attackers to execute code in privileged System Management Mode (SMM).
2. Exploitation bypasses Secure Boot and Intel BootGuard, enabling persistent firmware-level malware undetectable by antivirus.
3. Gigabyte systems vulnerable through local/remote admin access during boot, sleep states, or normal operation.
4. Check Gigabyte support website and install latest UEFI firmware updates immediately.

Technical Details of the Vulnerabilities

The discovered vulnerabilities stem from improper validation in SMI (System Management Interrupt) handlers within Gigabyte’s UEFI firmware implementations. 

Four distinct CVE identifiers have been assigned to these flaws: CVE-2025-7029, CVE-2025-7028, CVE-2025-7027, and CVE-2025-7026. 

These vulnerabilities exploit weaknesses in how the firmware handles data validation when processing SMI requests, particularly through unchecked register usage and inadequate pointer validation.

CVE-2025-7029 involves unchecked use of the RBX register, allowing attackers to control OcHeader and OcData pointers used in power and thermal configuration logic, resulting in arbitrary SMRAM (System Management RAM) writes. 

CVE-2025-7028 lacks validation of function pointer structures derived from RBX and RCX registers, enabling attacker control over critical flash operations, including ReadFlash, WriteFlash, EraseFlash, and GetFlashInfo functions through compromised FuncBlock structures.

CVE-2025-7027 presents a double pointer dereference vulnerability involving memory write operations from an unvalidated NVRAM Variable SetupXtuBufferAddress, while CVE-2025-7026 allows attackers to use the RBX register as an unchecked pointer within the CommandRcx0 function, enabling writes to attacker-specified memory locations in SMRAM.

The vulnerabilities enable attackers with local or remote administrative privileges to achieve code execution at Ring-2 privilege level, effectively bypassing all operating system-level protections, reads the CERT/CC report.

SMM operates below the OS kernel, making these attacks particularly dangerous as they can persist through system reboots and remain undetected by traditional endpoint protection solutions.

Exploitation can occur through multiple vectors including SMI handlers triggered from within the operating system, or during critical system states such as early boot phases, sleep transitions, or recovery modes before the OS fully loads. 

Successful exploitation allows attackers to disable crucial UEFI security mechanisms, creating opportunities for stealthy firmware implants and establishing persistent system control.

The Binarly Research team responsibly disclosed these vulnerabilities to CERT/CC, with Gigabyte’s PSIRT providing timely collaboration. 

CVE IdentifierDescriptionCVSS 3.1 ScoreSeverity
CVE-2025-7029Unchecked RBX register enables arbitrary SMRAM writes via OcHeader/OcData pointers9.8Critical
CVE-2025-7028Unvalidated function pointers allow attacker control over flash operations9.8Critical
CVE-2025-7027Double pointer dereference enables arbitrary SMRAM writes9.8Critical
CVE-2025-7026Unchecked RBX register allows arbitrary SMRAM writes in CommandRcx09.8Critical

Gigabyte has released updated firmware to address these vulnerabilities and strongly advises users to visit their support site to determine system impact and apply necessary updates. 

According to AMI, the original firmware supplier, these vulnerabilities were previously addressed through private disclosures, yet the vulnerable implementations persisted in some OEM firmware builds.

Users should immediately check for firmware updates and monitor vendor advisories, as these supply chain vulnerabilities may affect other PC OEM vendors beyond Gigabyte.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now 

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago