GIGABYTE Support:
CVE-2025-33043, CVE-2025-2884, CVE-2025-3052
Jul 18, 2025
Giga Computing Technology Co., Ltd. acknowledges the security vulnerabilities affecting GIGABYTE’s server, workstation, and motherboard products. The affected platforms are listed below.
| Platform | BIOS Release Schedule |
|---|---|
| CVE-2025-33043 | |
| AMD EPYC™ 9005 Series Processors [1] | Released |
| AMD EPYC™ 9004 Series Processors [1] | Released |
| AMD EPYC™ 8004 Series Processors | Released |
| AMD EPYC™ 7003 Series Processors | Released |
| AMD EPYC™ 7002 Series Processors | Released |
| AMD Instinct™ MI300A APU | Released |
| AMD EPYC™ 4005/4004 & Ryzen™ 9000/7000 Series Processors | Released |
| Intel® Xeon® 6 Processors | Released |
| 5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series | Released |
| 3rd Gen Intel® Xeon® Scalable Processors | Released |
| Intel® Xeon® E-2400 Series | Released |
| Intel® Xeon® E-2300 Series | Released |
| Intel® Xeon® W-3500/2500/3400/2400 Processors | Released |
| 14th/13th/12th Gen Intel® Core™ Processors | Released |
| CVE-2025-2884 | |
| AMD EPYC™ 4005/4004 & Ryzen™ 9000/7000 Series Processors | Released |
The vulnerabilities are listed below. Updated BIOS versions to address the threats will be available on all affected product pages.
Common Vulnerabilities or Exposures (CVEID): CVE-2025-33043
Severity Rating: Medium
Description: APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exploitation of this vulnerability can potentially impact of integrity.
Common Vulnerabilities or Exposures (CVEID): CVE-2025-2884
Severity Rating: Medium
Description: TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0
Source:












