{"id":"AZL-66108","summary":"CVE-2025-3770 affecting package edk2 for versions less than 20240524git3e722403cd16-9","details":"EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.","modified":"2026-04-01T05:20:42.260318Z","published":"2025-08-07T01:15:25Z","upstream":["CVE-2025-3770"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3770"}],"affected":[{"package":{"name":"edk2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/edk2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20240524git3e722403cd16-9"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66108.json"}}],"schema_version":"1.7.5"}