CVE-2025-33045 HIGH

CVE-2025-33045: Legacy Serial Redirection SMRAM Vulnerabilities

Vendor Ami
Product AptioV
Weakness CWE-123
Published September 9, 2025
Last update September 9, 2025

CVSS base score

8.2/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure of Sensitive Information to an Unauthorized Actor” through local access. The successful exploitation of these vulnerabilities can lead to information disclosure, arbitrary data writing, and impact Confidentiality, Integrity, and Availability.

Key dates

02Disclosure timeline

September 9, 2025 CVE published
September 9, 2025 Record updated