Snag the Best Deals on Products You Love – Handpicked Finds, Daily Discounts!

New UEFI Firmware Flaw Exposes Fashionable Motherboards To Assaults

Cybersecurity specialists simply discovered a flaw in the UEFI firmware that many trendy motherboards use. The “bug” may let attackers do direct reminiscence entry (DMA) assaults on techniques, which can allow unauthorized customers to achieve deep and protracted entry to affected techniques below sure circumstances, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.

To offer you context, the PC motherboard incorporates low-level software program known as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} parts. One in every of its main safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s supposed to safeguard system reminiscence. If arrange accurately, the IOMMU stops exterior units from studying or writing to random components of system RAM.

Parts resembling PCIe growth playing cards, Thunderbolt peripherals, GPUs, and comparable {hardware} that may entry reminiscence straight with out passing by the CPU are included in DMA-capable units. Malicious or compromised {hardware} can have much less of an affect as a result of these units are restricted to specific reminiscence areas if the IOMMU is operational and correctly initialized.

The just lately found vulnerability is brought on by the fallacious means this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, despite the fact that the IOMMU was by no means totally or accurately arrange, after which the working system consequently assumes that reminiscence protections are carried out, despite the fact that they don’t seem to be actively enforced.

The problem is being tracked below a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options in another way.

Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, have been the primary ones to determine the vulnerability. Vanguard, Riot’s anti-cheat system, is carried out on the kernel degree and incorporates safeguards which can be supposed to forestall unauthorized system manipulation. Valorant could also be prevented from launching on techniques which can be affected by this particular flaw, as it detects an unsafe {hardware} safety state.

There may be an essential limitation to consider, despite the fact that the potential impact may very well be horrible: the flexibility to bodily entry the system and join a malicious PCIe or comparable system earlier than the working system boots up are conditions for a DMA assault. Consequently, the chance of widespread exploitation is considerably diminished, significantly for residential customers.

Customers are being suggested to monitor updates from their motherboard producers and apply any obtainable firmware patches. Updating the UEFI firmware continues to be important to preserving system safety, significantly in mild of the continued evolution of hardware-level assaults.

Filed in Computers. Learn extra about , , , and .

Trending Merchandise

- 42% ANTEC AX61 Mid-Tower ATX Gaming Cas...
Original price was: $111.06.Current price is: $64.95.

ANTEC AX61 Mid-Tower ATX Gaming Cas...

0
Add to compare
- 38% PHILIPS 22 inch Class Skinny Full H...
Original price was: $113.38.Current price is: $69.99.

PHILIPS 22 inch Class Skinny Full H...

0
Add to compare
- 33% Thermaltake View 200 TG ARGB Mother...
Original price was: $119.99.Current price is: $79.99.

Thermaltake View 200 TG ARGB Mother...

0
Add to compare
- 10% LG FHD 32-Inch Pc Monitor 32ML600M-...
Original price was: $199.99.Current price is: $179.99.

LG FHD 32-Inch Pc Monitor 32ML600M-...

0
Add to compare
- 33% AMANSON PC CASE ATX 9 PWM ARGB Fans...
Original price was: $188.99.Current price is: $125.99.

AMANSON PC CASE ATX 9 PWM ARGB Fans...

0
Add to compare
- 17% ASUS RT-AX88U PRO AX6000 Twin Band ...
Original price was: $269.99.Current price is: $223.55.

ASUS RT-AX88U PRO AX6000 Twin Band ...

0
Add to compare
- 34% Cudy New AX3000 Twin Band Wi-Fi 6 R...
Original price was: $106.25.Current price is: $69.90.

Cudy New AX3000 Twin Band Wi-Fi 6 R...

0
Add to compare
- 40% HP 2024 Latest Laptop computer | 15...
Original price was: $1,007.98.Current price is: $599.99.

HP 2024 Latest Laptop computer | 15...

0
Add to compare
- 13% SABLUTE Wi-fi Keyboard and Mouse Co...
Original price was: $45.99.Current price is: $39.99.

SABLUTE Wi-fi Keyboard and Mouse Co...

0
Add to compare
- 42% 15.6” Laptop computer 12GB DD...
Original price was: $415.18.Current price is: $239.99.

15.6” Laptop computer 12GB DD...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

SnagzyFinds
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart