Discover Daily Deals on Top-Rated Products – Handpicked for Quality, Priced for Smart Shoppers!

New UEFI Firmware Flaw Exposes Well-liked Motherboards To Assaults

Cybersecurity specialists simply discovered a flaw in the UEFI firmware that many fashionable motherboards use. The “bug” may let attackers do direct reminiscence entry (DMA) assaults on methods, which can allow unauthorized customers to achieve deep and chronic entry to affected methods below sure situations, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.

To provide you context, the PC motherboard accommodates low-level software program known as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} parts. Certainly one of its major safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s meant to safeguard system reminiscence. If arrange appropriately, the IOMMU stops exterior gadgets from studying or writing to random components of system RAM.

Elements reminiscent of PCIe growth playing cards, Thunderbolt peripherals, GPUs, and related {hardware} that may entry reminiscence instantly with out passing via the CPU are included in DMA-capable gadgets. Malicious or compromised {hardware} can have much less of an impression as a result of these gadgets are restricted to specific reminiscence areas if the IOMMU is operational and correctly initialized.

The just lately found vulnerability is attributable to the flawed manner this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, although the IOMMU was by no means totally or appropriately arrange, after which the working system consequently assumes that reminiscence protections are applied, although they don’t seem to be actively enforced.

The difficulty is being tracked below a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options in a different way.

Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, had been the primary ones to determine the vulnerability. Vanguard, Riot’s anti-cheat system, is applied on the kernel degree and incorporates safeguards which can be meant to forestall unauthorized system manipulation. Valorant could also be prevented from launching on methods which can be affected by this particular flaw, as it detects an unsafe {hardware} safety state.

There’s an necessary limitation to consider, although the potential impact could possibly be horrible: the flexibility to bodily entry the system and join a malicious PCIe or related system earlier than the working system boots up are conditions for a DMA assault. Consequently, the chance of widespread exploitation is considerably diminished, significantly for residential customers.

Customers are being suggested to monitor updates from their motherboard producers and apply any out there firmware patches. Updating the UEFI firmware continues to be important to preserving system safety, significantly in gentle of the continued evolution of hardware-level assaults.

Filed in Computers. Learn extra about , , , and .

Trending Merchandise

- 50% GIM Micro ATX PC Case with 2 Temper...
Original price was: $79.99.Current price is: $39.99.

GIM Micro ATX PC Case with 2 Temper...

0
Add to compare
- 39% LG 24MP60G-B 24″ Full HD (192...
Original price was: $163.98.Current price is: $99.99.

LG 24MP60G-B 24″ Full HD (192...

0
Add to compare
- 34% Motorola MG7550 – Modem with ...
Original price was: $182.32.Current price is: $119.95.

Motorola MG7550 – Modem with ...

0
Add to compare
- 31% Lenovo IdeaPad 1 Student Laptop, 15...
Original price was: $491.55.Current price is: $339.00.

Lenovo IdeaPad 1 Student Laptop, 15...

0
Add to compare
- 36% SAMSUNG 27″ CF39 Series FHD 1...
Original price was: $266.88.Current price is: $169.99.

SAMSUNG 27″ CF39 Series FHD 1...

0
Add to compare
- 13% Wireless Keyboard and Mouse Combo, ...
Original price was: $39.99.Current price is: $34.99.

Wireless Keyboard and Mouse Combo, ...

0
Add to compare
- 32% MOFII Wireless Keyboard and Mouse C...
Original price was: $58.79.Current price is: $39.99.

MOFII Wireless Keyboard and Mouse C...

0
Add to compare
- 22% Logitech MK120 Wired Keyboard and M...
Original price was: $19.99.Current price is: $15.69.

Logitech MK120 Wired Keyboard and M...

0
Add to compare
- 26% Acer Nitro 31.5″ FHD 1920 x 1...
Original price was: $229.99.Current price is: $169.99.

Acer Nitro 31.5″ FHD 1920 x 1...

0
Add to compare
- 43% Lenovo IdeaPad 1 14 Laptop, 14.0&#8...
Original price was: $279.65.Current price is: $158.89.

Lenovo IdeaPad 1 14 Laptop, 14.0...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

EliteDealsGo
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart