Vulnerabilities

Lenovo UEFI firmware driver bugs affect over 100 laptop models

0

Lenovo published a security advisory on three vulnerabilities that impacts its Unified Extensible Firmware Interface (UEFI) loaded on around 100 of its laptop models.

Out of the three security issues that were discovered, two vulnerabilities allow an attacker to disable the protection for the SPI flash memory chip where the UEFI firmware is stored and to turn off the UEFI Secure Boot feature, which ensures the system loads at boot time only code trusted by the Original Equipment Manufacturer (OEM).

On successful exploitation of the third vulnerability, tracked as CVE-2021-3970, a local attacker could execute arbitrary code with elevated privileges.

The vulnerabilities were discovered by ESET researchers and reported to Lenovo in October last year. They affect more than 100 consumer laptop models, including IdeaPad 3, Legion 5 Pro-16ACH6 H, and Yoga Slim 9-14ITL05, which accounts to millions of users with vulnerable devices.

According to the researchers at ESET, the two UEFI-related vulnerabilities (CVE-2021-3971 and CVE-2021-3972) can be used by attackers to “deploy and successfully execute SPI flash or ESP implants.”

CVE-2021-3971: A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.

CVE-2021-3972: A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

A detailed technical analysis of the three vulnerabilities are provided by the researchers noting that “UEFI threats can be extremely stealthy and dangerous” because they execute “early in the boot process, before transferring control to the operating system.”

This means that most mitigations and security solutions active at the OS level are useless and payload execution is almost unavoidable and undetectable.

Detecting them is possible, but the process requires more advanced techniques like UEFI integrity checks, analyzing the firmware in real time, or monitoring the firmware behavior and the device for suspicious activity.

In order to protect against attacks from the above vulnerabilities, Lenovo recommends users of affected devices to update the system firmware version to the latest available. Users can do this by installing the update manually from the support page of the device or with the help of utilities for updating system drivers provided by the company.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Okta says Lapsus$ breach impacted only two of its customers

Previous article

Five Eyes advisory warns of Russia linked cyber attacks

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *