Intel has confirmed the authenticity of the UEFI firmware and BIOS source codes published by an unknown source on GitHub. A total of 5.8 GB of code, utilities, documentation, blobs, and settings related to firmware creation for systems with processors based on the Alder Lake microarchitecture, released in November 2021, were published. The most recent update to the published code is dated September 30, 2022.
According to Intel, the leak occurred due to a third party and not as a result of a compromise of the company's infrastructure. It is also mentioned that the publicly accessible code includes the Project Circuit Breaker program, which offers rewards ranging from $500 to $100,000 for identifying security issues in Intel's firmware and products (implying that researchers may receive rewards for reporting vulnerabilities discovered using the leaked content).
It is not specified who the source of the leak is (OEM hardware manufacturers and companies developing custom firmware had access to the firmware building toolkit). During the analysis of the published archive's contents, some product-specific tests and services from Lenovo were identified ('Lenovo Feature Tag Test Information', 'Lenovo String Service', 'Lenovo Secure Suite', 'Lenovo Cloud Service'), but Lenovo's involvement in the leak has not yet been confirmed. The archive also revealed utilities and libraries from Insyde Software, which develops firmware for OEM manufacturers, and the git log contains the email of an employee from LC Future Center, which produces laptops for various OEMs. Both companies collaborate with Lenovo.
According to Intel, the leaked code does not contain any confidential data or components that could lead to the disclosure of new vulnerabilities. However, Mark Ermolov, who specializes in researching Intel platform security, identified undocumented MSR (Model Specific Registers) information in the published archive, which is used for microcode control, tracing, and debugging. This information falls under a non-disclosure agreement. Moreover, the archive includes a private key used for signing firmware digitally, which could potentially be exploited to bypass Intel Boot Guard (the effectiveness of the key is unverified, and it may be a test key).
Source: opennet.ru
