Article 6GZA4 Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attack(ars technica)

Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attack(ars technica)

by
corbet
from LWN.net on (#6GZA4)
Thisars technica article describes how secure-boot firmware on a huge rangeof systems can be subverted with a malicious image file:

As its name suggests, LogoFAIL involves logos, specifically thoseof the hardware seller that are displayed on the device screenearly in the boot process, while the UEFI is still running. Imageparsers in UEFIs from all three major IBVs [independent BIOSvendors] are riddled with roughly a dozen critical vulnerabilitiesthat have gone unnoticed until now. By replacing the legitimatelogo images with identical-looking ones that have been speciallycrafted to exploit these bugs, LogoFAIL makes it possible toexecute malicious code at the most sensitive stage of the bootprocess.
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments