Vulnerabilities

Dozens of UEFI flaws impact millions of devices used by major vendors

0

New high severity security vulnerabilities have been disclosed in different implementations of Unified Extensible Firmware Interface (UEFI) firmware used by numerous vendors, including Bull Atos, Fujitsu, HP, Juniper Networks, Lenovo, among others.

According to enterprise firmware security company Binarly, as many as 23 vulnerabilities reside in Insyde Software’s InsydeH2O UEFI firmware, with a majority of the anomalies diagnosed in the System Management Mode (SMM).

UEFI is a software specification that provides a standard programming interface connecting a computer’s firmware to its operating system during the booting process. In x86 systems, the UEFI firmware is stored in the flash memory chip of the motherboard.

The researchers stated that by exploiting these vulnerabilities, it is possible for a threat actor to successfully install malware that survives operating system re-installations and allows the bypass of endpoint security solutions (EDR/AV), Secure Boot, and Virtualization-Based Security isolation.

On successful exploitation of the flaws (CVSS scores: 7.5 – 8.2), a malicious actor can run arbitrary code with SMM permissions, a special-purpose execution mode in x86-based processors that handles power management, hardware configuration, thermal monitoring, and other functions.

Microsoft reported that SMM code executes in the highest privilege level and is invisible to the OS. The SMM attack vector could be abused by a piece of evil code to trick another code with higher privileges into performing unauthorized activities.

The weaknesses can also be combined to bypass security features and install malware in a manner that survives operating system re-installations and achieve long-term persistence on compromised systems while stealthily creating a communications channel to exfiltrate sensitive data.

Insyde has released firmware patches that address these shortcomings as part of the coordinated disclosure process.

Image Credits : HakTechs

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Thousands of routers exposed to Eternal Silence attacks via UPnP

Previous article

Arid Viper hackers strike Palestine with political lures and Trojans

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *