Article 5KJ7H A well-meaning feature leaves millions of Dell PCs vulnerable

A well-meaning feature leaves millions of Dell PCs vulnerable

by
Eric Bangeman
from Ars Technica - All content on (#5KJ7H)
dell-building-800x533.jpg

Enlarge / Dell has released a patch for a set of vulnerabilities that left as many as 30 million devices exposed. (credit: Artur Widak | Getty Images)

Researchers have known for years about security issues with the foundational computer code known as firmware. It's often riddled with vulnerabilities, it's difficult to update with patches, and it's increasingly the target of real-world attacks. Now a well-intentioned mechanism to easily update the firmware of Dell computers is itself vulnerable as the result of four rudimentary bugs. And these vulnerabilities could be exploited to gain full access to target devices.

The new findings from researchers at the security firm Eclypsium affect 128 recent models of Dell computers, including desktops, laptops, and tablets. The researchers estimate that the vulnerabilities expose 30 million devices in total, and the exploits even work in models that incorporate Microsoft's Secured-core PC protections-a system specifically built to reduce firmware vulnerability. Dell is releasing patches for the flaws today.

Read 10 remaining paragraphs | Comments

index?i=ZeE42Ffop9A:lh0A4VouFnk:V_sGLiPB index?i=ZeE42Ffop9A:lh0A4VouFnk:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments