Privileged local BIOS code execution in AMI Aptio V (incomplete input validation)
AI analysis
AMI's Aptio V UEFI BIOS firmware contains an input-validation flaw classified as CWE-184 (Incomplete List of Disallowed Inputs), meaning a BIOS code path fails to reject all inputs it is supposed to disallow. Triggering it requires local access to the machine, and the CVSS 4.0 metrics show the attacker must already hold high privileges (typically OS-level administrator), with no user interaction needed but elevated attack prerequisites that must be met. Successful exploitation yields arbitrary code execution in the firmware context with high impact on confidentiality, integrity and availability on the affected system and, per the scoring, potentially on subsequent systems - significant for BIOS because firmware-level compromise can persist across OS reinstalls. Any workstation, server or motherboard shipped with AMI Aptio V firmware by an OEM is in scope. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported (EPSS 0.1%); a separate related AMI firmware issue (VU#718077, Secure Boot bypass via a UEFI Shell embedded in SPI flash) is also documented.
What to do: Check your motherboard or system vendor's support page for BIOS updates incorporating the AMI fix, since no affected-version list is provided here and OEMs package Aptio V fixes in their own BIOS releases. Until patched, restrict local administrative access on sensitive systems and treat this as a high-severity firmware fix rather than a routine BIOS update. While updating, also verify whether your system's SPI flash contains the embedded UEFI Shell module highlighted in VU#718077, which can be used to bypass Secure Boot.
Affected
| AMI (American Megatrends International) Aptio V (AptioV) UEFI BIOS firmware | — |
Estimated exposure
masson the order of tens of millions of installed systems (OEM boards shipping with AMI Aptio V firmware) — AMI is the dominant independent UEFI BIOS supplier and Aptio V is one of its current-generation firmware lines used by major motherboard and system OEMs, implying millions of shipped systems, though the attack surface is limited to users…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.