UEFI firmware from Microsoft, Intel, HP, Dell etc., can be at risk from nearly 20 different vulnerabilities
That is the InsydeH2O "Hardware-2-Operating System" UEFI BIOS, a software used by a series of major vendors in the computer field such as Microsoft, Intel, HP, Dell, Lenovo, Siemens, Fujitsu, etc., can be affected by more than two dozen different vulnerabilities, with ratings ranging from common to dangerous.
According to Binarly's investigation results, there are a total of 23 vulnerabilities that mainly affect System Management Mode (SMM). Information about these vulnerabilities is listed below along with their assigned security IDs.
Since these are all firmware-level vulnerabilities, successful exploitation can lead to persistent malware on the system that is almost impossible for users to completely remove.
Binarly describes the detected vulnerabilities as follows:
The majority of disclosed vulnerabilities (CVSS score: 7.5 - 8.2, high severity rating) resulted in code execution with SMM privileges. As part of the exploit chain, these vulnerabilities can be used as a second stage in a malicious process, to bypass security features or achieve long-term survival on the target system. [.]
By exploiting these vulnerabilities, attackers can successfully install malware that exists during the root of the operating system, and allows bypassing endpoint security solutions (EDRs). /AV), Secure Boot, Virtualization-Based Security.
The Binarly team first discovered these vulnerabilities on Fujitsu's LIFEBOOK notebook computers. After extensive investigation, it was quickly realized that not only Fujitsu, but also software from a variety of other manufacturers could be affected by these vulnerabilities. Cause because all are using InsydeH2O UEFI solutions.
You should read it
- AMD released a firmware update for Specter to fix the vulnerability on the CPU
- Things to note when using UEFI instead of BIOS
- How to enable / disable Fast Boot in UEFI firmware settings on Windows
- 6 replacement firmware for the router
- How to set a firmware password on a Mac
- What is firmware? How is Firmware different from Software?
- How to update 3D printer firmware
- DD-WRT, Tomato and OpenWrt - Where is the best firmware router?
May be interested
- Intel expects to end Legacy BIOS support by 2020intel expects to abandon bios legacy technology support in modern server and client chipsets by 2020. at that time, its products will only support uefi class 3 or newer versions. this information has been confirmed by intel's leading engineer, brian richardson.
- Intel's chip has eight new serious vulnerabilitiesseveral weeks ago, google project zero security experts discovered eight new vulnerabilities in intel's chip design, which could directly lead to specter and meltdown, two vulnerabilities that negatively impacted performance. whole computer system.
- Microsoft is about to add a useful security feature to Windows 10 to help detect software attacks earlyuefi scanner feature in the defender advanced threat protection (defender atp) tool.
- Serious security vulnerability on Intel chipseither leave the hole or install the patch to make it slower. how to choose it depends on you.
- AMD released a firmware update for Specter to fix the vulnerability on the CPUamd has allowed users to update the firmware for ryzen and epyc this week.
- Foreshadow - the fifth most serious security hole in the CPU in 2018this vulnerability could bypass intel sgx security measures. what a tiring year for microprocessors, especially intel.
- Dell XPS 14 and 15 officially launchedboth models use intel ivy bridge chips, ram 8gb and sold from yesterday in the us for $ 1,099 and $ 1,299 respectively.
- UEFI CosmicStrand Malware Found in ASUS and Gigabyte Firmwarethe security threat research team at antivirus software maker kaspersky has discovered a rootkit malware called cosmicstrand.
- Why Intel killed the BIOS, switched to UEFI?from here, we will not be able to boot dos and all other obsolete things.
- Differences between UEFI and BIOSwhich uefi or bios is better and which one to use? this is a good question for anyone who wants to learn how basic hardware works. the following is a list of differences between uefi and bios