Shop Smarter Every Day – Discover Top-Rated Products with Unbeatable Savings at ShopperSavingsHub

New UEFI Firmware Flaw Exposes Standard Motherboards To Assaults

Cybersecurity specialists simply discovered a flaw in the UEFI firmware that many fashionable motherboards use. The “bug” may let attackers do direct reminiscence entry (DMA) assaults on programs, which can allow unauthorized customers to achieve deep and protracted entry to affected programs beneath sure situations, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.

To offer you context, the PC motherboard comprises low-level software program known as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} elements. One in every of its major safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s meant to safeguard system reminiscence. If arrange accurately, the IOMMU stops exterior units from studying or writing to random components of system RAM.

Elements comparable to PCIe enlargement playing cards, Thunderbolt peripherals, GPUs, and comparable {hardware} that may entry reminiscence straight with out passing by the CPU are included in DMA-capable units. Malicious or compromised {hardware} can have much less of an affect as a result of these units are restricted to explicit reminiscence areas if the IOMMU is operational and correctly initialized.

The lately found vulnerability is attributable to the flawed approach this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, although the IOMMU was by no means totally or accurately arrange, after which the working system consequently assumes that reminiscence protections are carried out, although they aren’t actively enforced.

The problem is being tracked beneath a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options otherwise.

Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, have been the primary ones to determine the vulnerability. Vanguard, Riot’s anti-cheat system, is carried out on the kernel stage and incorporates safeguards which can be meant to forestall unauthorized system manipulation. Valorant could also be prevented from launching on programs which can be affected by this particular flaw, as it detects an unsafe {hardware} safety state.

There may be an essential limitation to consider, although the attainable impact could possibly be horrible: the flexibility to bodily entry the system and join a malicious PCIe or comparable system earlier than the working system boots up are conditions for a DMA assault. Consequently, the chance of widespread exploitation is considerably diminished, notably for residential customers.

Customers are being suggested to monitor updates from their motherboard producers and apply any out there firmware patches. Updating the UEFI firmware remains to be important to preserving system safety, notably in gentle of the continued evolution of hardware-level assaults.

Filed in Computers. Learn extra about , , , and .

Trending Merchandise

- 38% NZXT H5 Stream Compact ATX Mid-Towe...
Original price was: $151.32.Current price is: $93.99.

NZXT H5 Stream Compact ATX Mid-Towe...

0
Add to compare
- 27% MATX PC Case, 6 ARGB Followers Pre-...
Original price was: $109.59.Current price is: $79.99.

MATX PC Case, 6 ARGB Followers Pre-...

0
Add to compare
- 18% LG UltraWide QHD 34-Inch Pc Monitor...
Original price was: $399.99.Current price is: $329.00.

LG UltraWide QHD 34-Inch Pc Monitor...

0
Add to compare
- 7% Acer Aspire 1 A115-32-C96U Slim Lap...
Original price was: $229.99.Current price is: $214.99.

Acer Aspire 1 A115-32-C96U Slim Lap...

0
Add to compare
- 28% Dell Inspiron 15 3520 15.6″ F...
Original price was: $743.82.Current price is: $539.00.

Dell Inspiron 15 3520 15.6″ F...

0
Add to compare
- 19% Wi-fi Keyboard and Mouse Combo &#82...
Original price was: $20.99.Current price is: $16.99.

Wi-fi Keyboard and Mouse Combo R...

0
Add to compare
- 17% ASUS RT-AX88U PRO AX6000 Dual Band ...
Original price was: $269.99.Current price is: $223.55.

ASUS RT-AX88U PRO AX6000 Dual Band ...

0
Add to compare
- 35% Logitech MK270 Wi-fi Keyboard And M...
Original price was: $43.01.Current price is: $27.93.

Logitech MK270 Wi-fi Keyboard And M...

0
Add to compare
- 32% Wired Keyboard and Mouse Combo, EDJ...
Original price was: $30.86.Current price is: $20.99.

Wired Keyboard and Mouse Combo, EDJ...

0
Add to compare
- 15% HP 17.3″ FHD Enterprise Lapto...
Original price was: $649.00.Current price is: $549.00.

HP 17.3″ FHD Enterprise Lapto...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

ShopperSavingsHub
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart