LogoFAIL: New Firmware Attack Exploits UEFI Vulnerabilities on Windows and Linux Devices

1 min read
Source: Ars Technica
LogoFAIL: New Firmware Attack Exploits UEFI Vulnerabilities on Windows and Linux Devices
Photo: Ars Technica
TL;DR Summary

A new firmware attack called LogoFAIL has been discovered, affecting hundreds of Windows and Linux computer models from various hardware makers. The attack exploits vulnerabilities in Unified Extensible Firmware Interfaces (UEFIs) responsible for booting devices, allowing for the execution of malicious firmware early in the boot-up sequence. LogoFAIL can be remotely executed and bypasses traditional endpoint security products, including Secure Boot. The vulnerabilities have been disclosed by multiple companies, and security patches are being released. The attack gives threat actors control over the memory and disk of the target device, compromising platform security.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

3 min

vs 4 min read

Condensed

86%

67193 words

Want the full story? Read the original article

Read on Ars Technica