"UEFI Vulnerabilities Enable Stealth Malware Attacks and Secure Boot Bypass on Millions of PCs"

1 min read
Source: The Hacker News
"UEFI Vulnerabilities Enable Stealth Malware Attacks and Secure Boot Bypass on Millions of PCs"
Photo: The Hacker News
TL;DR Summary

Multiple vulnerabilities in the Unified Extensible Firmware Interface (UEFI) code, collectively known as LogoFAIL, have been discovered, allowing threat actors to deliver malicious payloads and bypass security technologies. By injecting a malicious logo image file into the EFI system partition, attackers can bypass security solutions and deliver persistent malware during the boot phase. The vulnerabilities affect both x86 and ARM-based devices and major independent firmware/BIOS vendors (IBVs) like AMI, Insyde, and Phoenix, impacting a wide range of consumer and enterprise-grade devices. These flaws highlight the need for improved code quality and product security maturity in IBVs reference code.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

76%

41298 words

Want the full story? Read the original article

Read on The Hacker News