Discover Elite Finds Daily – Top-Rated Products, Exclusive Deals, and Must-Have Essentials All in One Place.

New UEFI Firmware Flaw Exposes In style Motherboards To Assaults

Cybersecurity consultants simply discovered a flaw in the UEFI firmware that many trendy motherboards use. The “bug” might let attackers do direct reminiscence entry (DMA) assaults on techniques, which can allow unauthorized customers to realize deep and protracted entry to affected techniques beneath sure circumstances, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.

To provide you context, the PC motherboard comprises low-level software program known as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} parts. Considered one of its major safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s supposed to safeguard system reminiscence. If arrange accurately, the IOMMU stops exterior gadgets from studying or writing to random elements of system RAM.

Elements comparable to PCIe growth playing cards, Thunderbolt peripherals, GPUs, and related {hardware} that may entry reminiscence instantly with out passing by the CPU are included in DMA-capable gadgets. Malicious or compromised {hardware} can have much less of an affect as a result of these gadgets are restricted to specific reminiscence areas if the IOMMU is operational and correctly initialized.

The lately found vulnerability is brought on by the flawed means this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, though the IOMMU was by no means totally or accurately arrange, after which the working system consequently assumes that reminiscence protections are carried out, though they don’t seem to be actively enforced.

The problem is being tracked beneath a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options in a different way.

Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, have been the primary ones to establish the vulnerability. Vanguard, Riot’s anti-cheat system, is carried out on the kernel degree and incorporates safeguards which might be supposed to stop unauthorized system manipulation. Valorant could also be prevented from launching on techniques which might be affected by this particular flaw, as it detects an unsafe {hardware} safety state.

There may be an necessary limitation to consider, though the potential impact may very well be horrible: the power to bodily entry the system and join a malicious PCIe or related system earlier than the working system boots up are conditions for a DMA assault. Consequently, the likelihood of widespread exploitation is considerably diminished, notably for residential customers.

Customers are being suggested to monitor updates from their motherboard producers and apply any out there firmware patches. Updating the UEFI firmware continues to be important to preserving system safety, notably in gentle of the continuing evolution of hardware-level assaults.

Filed in Computers. Learn extra about , , , and .

Trending Merchandise

0
Add to compare
- 29% Dell Inspiron 15 3000 3520 Business...
Original price was: $703.45.Current price is: $498.90.

Dell Inspiron 15 3000 3520 Business...

0
Add to compare
- 30% HP 27h Full HD Monitor – Diag...
Original price was: $229.99.Current price is: $159.99.

HP 27h Full HD Monitor – Diag...

0
Add to compare
- 18% LG UltraWide QHD 34-Inch Pc Monitor...
Original price was: $399.99.Current price is: $329.00.

LG UltraWide QHD 34-Inch Pc Monitor...

0
Add to compare
- 31% Acer Nitro 27″ WQHD 2560 x 14...
Original price was: $289.99.Current price is: $199.99.

Acer Nitro 27″ WQHD 2560 x 14...

0
Add to compare
0
Add to compare
- 18% TP-Link AX5400 WiFi 6 Router (Arche...
Original price was: $169.99.Current price is: $139.99.

TP-Link AX5400 WiFi 6 Router (Arche...

0
Add to compare
- 28% Laptop computer Pc, 15.6 Inch FHD S...
Original price was: $347.49.Current price is: $249.99.

Laptop computer Pc, 15.6 Inch FHD S...

0
Add to compare
- 16% ASUS VA24DQ 23.8” Monitor, 1080P ...
Original price was: $129.00.Current price is: $109.00.

ASUS VA24DQ 23.8” Monitor, 1080P ...

0
Add to compare
0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

EliteFindsToday
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart