Lenovo? inform immediately

More than 25 Lenovo laptops are vulnerable to malicious attacks that disable the UEFI secure boot process and then run unsigned UEFI apps or load bootloaders to permanently backdoor devices.

Lenovo

At the same time that researchers from security firm ESET uncovered the vulnerabilities, the laptop maker released security updates for 25 models, including ThinkPads, Yoga Slims and IdeaPads. The security gaps that undermine the UEFI boot are serious because they allow attackers to install malicious firmware that survives operating system formats.

The Unified Extensible Firmware Interface, or UEFI is the software that bridges a computer's firmware with the of the system. As the first piece of code that runs when a computer starts up, it is the first link in the security chain. Because UEFI resides on a flash chip on the motherboard, infections are very difficult to detect and remove.

Standard measures such as one of the hard drive and reinstalling the operating system does not help, because the infected UEFI will infect the computer again when it starts.

Η ESET είπε ότι τα κενά ασφαλείας CVE-2022-3430, CVE-2022-3431 και CVE-2022-3432, επιτρέπουν την απενεργοποίηση της ασφαλούς εκκίνησης UEFI ή την επαναφορά των εργοστασιακών προεπιλεγμένων ρυθμίσεων της of secure boot data (and dbx). Secure Boot uses databases to allow and deny mechanisms. The DBX database, in particular, stores encrypted hashes of denied keys.

Disabling or resetting databases to default values ​​allows an attacker to override restrictions that would normally apply.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.083 registrants.
Lenovo

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).