{"id":"AZL-66119","summary":"CVE-2025-3770 affecting package edk2 for versions less than 20230301gitf80f052277c8-43","details":"EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.","modified":"2026-04-01T05:20:42.249078Z","published":"2025-08-07T01:15:25Z","upstream":["CVE-2025-3770"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3770"}],"affected":[{"package":{"name":"edk2","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/edk2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20230301gitf80f052277c8-43"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66119.json"}}],"schema_version":"1.7.5"}