Database/Firmware, BMC & network fabric

AMI AptioV UEFI BIOS: A time-of-check-to-time-of-use race in the BIOS leading to arbitrary code execution
Impact
A time-of-check-to-time-of-use race in the BIOS leading to arbitrary code execution with a changed scope. This is the quiet half of the March 2025 AMI advisory - it shipped alongside the CVSS 10.0 MegaRAC authentication bypass that got all the attention, and most operators patched the BMC and forgot the BIOS. Successful exploitation puts attacker code in the firmware boot path, below the OS and below any EDR you run, on a node that will keep passing every host-level integrity check you have.
Who can reach it
Local access with high privileges, high attack complexity. Needs root or kernel code on the host plus the ability to win a timing window during a firmware operation. On bare-metal GPU rentals the tenant holds that privilege by contract; on managed nodes it requires a prior host compromise.
What to do
BIOS update to BKC_5.38 or later - firmware flash plus a full host reboot, per node, gated on your server vendor rebasing. Check specifically whether your March 2025 remediation covered the BIOS: many fleets flashed only the MegaRAC fix for CVE-2024-54085 from the same advisory and left this one open. No config-only mitigation exists for a TOCTOU in firmware.
References
Related entries
- AMI AptioV UEFI BIOS: A race condition in the BIOS that a skilled local attacker can drive to resource exhaustionCVE-2025-22830 · AMI AptioV UEFI BIOSHigh
- AMI AptioV UEFI BIOS: Improper handling of insufficient permissions in the BIOS lets a low-privileged local userCVE-2025-58770 · AMI AptioV UEFI BIOSHigh
- AMI AptioV UEFI BIOS: Improper input validation in the BIOS with an integrity impact and a changed scopeCVE-2025-33043 · AMI AptioV UEFI BIOSMedium
- Insyde InsydeH2O (UsbCoreDxe SMM module): Another SMM callout in the USB core driverCVE-2024-55567 · Insyde InsydeH2O (UsbCoreDxe SMM module)High
- GRUB2 (network config file search): grub_net_search_config_file copies a network-controlled variable with strcpyCVE-2025-0624 · GRUB2 (network config file search)High
- Linux kernel (drivers/infiniband/hw/bnxt_re): The NVMe-oF target host panics the moment a client connects.CVE-2025-21885 · Linux kernel (drivers/infiniband/hw/bnxt_re)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.