Jump to content

logoFAIL vulnerability


tgw

Recommended Posts

For the past weeks, the internet has been awash with warnings about that UEFI / BIOS vulnerability, urging everyone to look for mobo manufacturers' firmware patches and update their mobo firmware.

 

Hackers can exploit that vulnerability if they replace the logo image file within the BIOS firmware. And that code has to somehow get there in the first place.

 

In other words, the hacker needs to find a way into a target system by other means – such as an unpatched security flaw – and gain elevated privileges, or via a physical attack vector by using an BIOS flash program to inject the malicious image.

 

This could be a real threat to organizations where people have physical access to machines.

 

For home users, the threat should be very limited if their software is up-to-date, but anyone who is potentially a target should be aware of the vulnerability.

 

And doubly aware :

 

1- it's still possible to be targeted by hackers using zero-day exploits that will enable the attack vector

 

2- rushing to manufacturers' websites to download firmware updates could potentially lead to disaster if the manufacturer's website has been spoofed, or if a man-in-the-middle attack delivers the wrong file to the downloader.

 

In the case #2, it would mean that making the target aware of the threat, and if then the target takes the expected action, would also enable the attack. Very elegant.

 

 

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.




×
×
  • Create New...