CERT-In Vulnerability Note
CIVN-2025-0385
Multiple Vulnerabilities in Multiple Motherboards
Original Issue Date:December 24, 2025
Severity Rating: HIGH
Software Affected
- ASRock motherboards using Intel 500, 600, 700, and 800 series chipsets
- ASUS motherboards using Intel Z490, W480, B460, H410, Z590, B560, H510, Z690, B660, W680, Z790, B760, and W790 series chipsets
- GIGABYTE motherboards using Intel Z890, W880, Q870, B860, H810, Z790, B760, Z690, Q670, B660, H610, W790 series chipsets
- AMD motherboards using Intel X870E, X870, B850, B840, X670, B650, A620, A620A series chipsets
- MSI motherboards using Intel 600 and 700 series chipsets
Overview
A vulnerability has been reported in multiple motherboards, which could be exploited by an attacker to bypass security restrictions and compromise the integrity of the targeted system.
Target Audience: All end-user organisations and individuals using ASRock, ASUS, GIGABYTE, AMD and MSI motherboards
Impact Assessment: Potential for Elevation of Privilege.
Description
These vulnerabilities exist due to improper enforcement of DMA protections during the early boot phase, which could allow a local attacker with physical access to exploit a malicious PCIe device to gain unauthorised access to system memory before the operating system loads.
Successful exploitation of these vulnerabilities could allow the attacker to bypass security restrictions and compromise the integrity of the targeted system.
Solution
Apply the security updates released by the vendors:
https://www.asrock.com/support/Security.asp
https://csr.msi.com/global/product-security-advisories
https://www.gigabyte.com/Support/Security?type=1
https://www.asus.com/security-advisory/
Vendor Information
https://www.asrock.com/support/Security.asp
https://csr.msi.com/global/product-security-advisories
https://www.gigabyte.com/Support/Security?type=1
https://www.asus.com/security-advisory/
References
https://www.securityweek.com/uefi-vulnerability-in-major-motherboards-enables-early-boot-attacks/
CVE Name
CVE-2025-11901
CVE-2025-14302
CVE-2025-14303
CVE-2025-14304
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|