Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
Excellentpix Excellentpix

Intelligence Redefined

Excellentpix Excellentpix

Intelligence Redefined

  • Green Energy
  • Tech News
  • Gadget
  • Smartphone
  • Laptop
  • PC
  • About Us
    • Advertise Here
    • Contact Us
    • Privacy Policy
    • Sitemap
  • Green Energy
  • Tech News
  • Gadget
  • Smartphone
  • Laptop
  • PC
  • About Us
    • Advertise Here
    • Contact Us
    • Privacy Policy
    • Sitemap
Subscribe
Close

Search

Laptop

23 Major BIOS Vulnerabilities Discovered, Impact Intel, Lenovo, Others

By Maria H. Gray
February 2, 2022 2 Min Read
Comments Off on 23 Major BIOS Vulnerabilities Discovered, Impact Intel, Lenovo, Others

News has emerged of 23 new vulnerabilities that are particularly nefarious because the UEFI/BIOS-based attacks bypass security mechanisms and persist after drive formats and system re-installations, and attackers can exploit the vulnerabilities remotely. Security experts at Binarly have discovered 23 high-impact vulnerabilities hiding in BIOS/UEFI software from a multitude of system vendors, including Intel, Microsoft, Lenovo, Dell, Fujitsu, HP, HPE, Siemens, and Bull Atos (via Bleeping Computer). These vulnerabilities include SMM Callout or Privilege Escalation, SMM Memory Corruption, and DXE Memory corruption. 

Last week found news emerged of the MoonBounce malware that hides in your BIOS chip, but Binarly’s disclosure indicates a wide range of UEFI vulnerabilities that can be used as a springboard to install malware, or even new infected firmware images. 

The impact of these vulnerabilities is severe because they can be used by attackers to bypass security features such as Secure Boot, Virtualization-Based Security (VBS), and even Trusted Platform Modules (TPM). The vulnerabilities exist in the UEFI but also allow malware to be installed on the system and will survive operating system reinstallations, making the malware nearly undetectable and indestructible.

Binarly found the issue causing all these vulnerabilities were associated with InsydeH20, a firmware framework code used to build motherboard BIOS’s/UEFI’s. All the appropriate vendors were using Insyde’s firmware SDK for motherboard development.

The investigation began when Binarly discovered several repeatable anomalies on twenty different enterprise machines, from Fujitsu and its Lifebook laptops. However, once Binarly delved deeper into the problem, it discovered that a lot more OEMs were also having the same problems.

After discovering the issues, Binarly immediately reported the problems to the CERT/CC, a Vulnerability Notes Database that provides detail about software vulnerabilities. Together, both the CERT/CC and Binarly were able to contact all 25 impacted vendors.

If you’re worried about infection, there will be a way you can check and see if your computer is infected with these exploits. Binarly developed a piece of software called FwHunt that can detect vulnerable code patterns. But for now, the rules remain hidden and will be revealed through GitHub once the vulnerability advisory becomes public.

As for a real fix, we don’t have a set date on official firmware patches. However, Binarly notes that using the VINCE platform for communicating with multiple vendors/parties allows them to reduce the security fix timeline down to 5 months. That means we can expect official firmware updates to happen around the second half of 2022.

Source News

Tags:

impactIntelLenovoMajor
Author

Maria H. Gray

Follow Me
Other Articles
Previous

Secret iPhone emoji trick added with new update and fans are going wild for it

Next

Arid Viper hackers strike Palestine with political lures and Trojans

October 2026
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Sep    

Archives

Categories

  • Car
  • Entertainment
  • Gadget
  • Games
  • general
  • Green Energy
  • internet marketing
  • IT Solutions
  • Laptop
  • Lifestyle
  • PC
  • Property
  • Real estate
  • SEO
  • Smartphone
  • Software Company
  • Start Up
  • Tech News
  • Technology
  • uncategorized

Recent Posts

  • Nemanex en gouttes : comment lire un avis avant d’essayer un complément alimentaire
  • Casino en ligne — Étapes d’un dépôt et d’un retrait: Spinboss
  • Nettikasino — Flamez: Talletus- ja nostojen vaiheet: Pelit ja talletukset: käytännöllinen katsaus olennaisiin tietoihin
  • HIPAA EDI Transactions Explained: 834, 835, 837, 270/271, 276/277, 278 and 820
  • AI-Powered Phishing Is Getting Better: How Staff Training Needs to Change in 2026

fiver

Fiverr Logo

Tags

Amazon Android announces app Apple Big Black Buy Car coming deals Electric Galaxy game games gaming Google Heres Hunter iPhone laptop Laptops launch Market Microsoft news phone Pro Release Review sale Sales Samsung Series Smartphone software startup startups Stock tech Tesla top Windows Xbox year

PHP 2026

cafeaberto
urebike

BL

excellentpix.com

WhatsApp us