Vulnerabilities in UEFI firmware based on the InsydeH2O framework allow code execution at the SMM level.

In the InsydeH2O framework, used by many manufacturers to create UEFI firmware for their hardware (the most common implementation of UEFI BIOS), 23 vulnerabilities have been identified that enable code execution at the SMM (System Management Mode) level, which is more privileged (Ring -2) than the hypervisor mode and the zero privilege ring, granting unrestricted access to all memory. This issue affects UEFI firmware used by manufacturers such as Fujitsu, Siemens, Dell, HP, HPE, Lenovo, Microsoft, Intel, and Bull Atos.

Exploitation of the vulnerabilities requires local access with administrator rights, making these issues sought after as second-tier vulnerabilities, used after the exploitation of other vulnerabilities within the system or through social engineering methods. SMM-level access can be used to execute code at a level not controlled by the operating system, which could be utilized to modify firmware and leave hidden malware or rootkits in SPI Flash that are undetectable from the operating system, as well as to disable verification during the boot phase (UEFI Secure Boot, Intel BootGuard) and attack hypervisors to bypass integrity-check mechanisms of virtual environments.

Vulnerabilities in UEFI firmware based on the InsydeH2O framework allow code execution at the SMM level.

Exploitation of the vulnerabilities can be carried out from the operating system using unverified SMI handlers (System Management Interrupt), as well as during the boot process prior to the operating system execution or when resuming from sleep. All vulnerabilities are caused by memory handling issues and are divided into three categories:

  • SMM Callout — executing custom code with SMM privileges by redirecting the execution of SWSMI interrupt handlers to code outside of SMRAM;
  • Memory corruption allowing an attacker to write their data into SMRAM, a special isolated memory area where code with SMM privileges executes.
  • Memory corruption in code executed at the DXE (Driver eXecution Environment) level.

To demonstrate the principles of attack organization, an example exploit has been published that allows access to the DXE Runtime UEFI through an attack from the third or zero defense ring, enabling the execution of custom code. The exploit manipulates a stack overflow (CVE-2021-42059) in the UEFI DXE driver. During the attack, an attacker can place their code in the DXE driver, which remains active after the operating system is rebooted, or modify the NVRAM area in the SPI Flash. During execution, the attacker's code can alter privileged memory areas, modify EFI Runtime services, and influence the boot process.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster