Firmware flaws could allow a malicious reflash, US CERT warns

U.S. CERT warned of three issues that could affect critical firmware

Three vendors have released fixes for vulnerabilities found in the critical firmware used during a computer's startup, according to an advisory from the U.S. Computer Emergency Readiness Team.

The vulnerabilities could allow an attacker to bypass a feature called Secure Boot, which verifies that firmware components carry a correct digital signature ensuring the software's authenticity. The attacker could then replace the device's firmware.

The flaws lie within some UEFI (unified extensible firmware interface) systems, the advisory said. UEFI is a firmware interface that was designed to improve upon BIOS.

A boot script within the UEFI S3 Resume path "resides in unprotected memory which can be tampered with by an attacker with access to physical memory," the advisory said.

An authenticated local attacker could bypass Secure Boot and reflash, or replace, the firmware even if signed firmware updates are supposed to be used. An attack could also cause a system to be inoperable.

Several vendors have taken action. American Megatrends Incorporated (AMI), which makes BIOS and UEFI firmware, has "addressed the issue on a generic basis and is working with OEMs to implement fixes for projects in the field and production."

Intel and Phoenix Technologies, which also makes UEFI software, have issued fixes, the advisory said.

The advisory was one of three issued by U.S. CERT on Monday. The agency also warned of a "race condition" vulnerability in some Intel chipsets that could allow the bypass of a BIOS locking mechanism, allowing malicious code to be inserted into firmware.

American Megatrends and Phoenix Technologies have issued updates to address the issue, but it's unknown if other major vendors may be affected, according to the advisory.

U.S. CERT also warned in a third advisory of a buffer overflow in the open-source EDK1 project's UEFI reference implementation. One affected vendor that uses the firmware, Insyde Software, has fixed the issue.

American Megatrends, Apple, IBM, Intel and Phoenix Technologies are not affected by that flaw. However, it's not known whether other large vendors may be vulnerable.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags AppleIBMsecurityU.S. Computer Emergency Readiness TeamInsyde SoftwareExploits / vulnerabilitiesAmerican MegatrendsintelPhoenix Technologies

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Cool Tech

Crucial Ballistix Elite 32GB Kit (4 x 8GB) DDR4-3000 UDIMM

Learn more >

Gadgets & Things

Lexar® Professional 1000x microSDHC™/microSDXC™ UHS-II cards

Learn more >

Family Friendly

Lexar® JumpDrive® S57 USB 3.0 flash drive 

Learn more >

Stocking Stuffer

Plox Star Wars Death Star Levitating Bluetooth Speaker

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

GGG Evaluation Team

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott

STYLISTIC Q702

My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?