LogoFAIL — an attack on UEFI firmware through the substitution of malicious logos

Researchers from Binarly have identified a series of vulnerabilities in the image parsing code used in UEFI firmware from various manufacturers. These vulnerabilities allow the execution of arbitrary code during boot by placing a specially crafted image in the ESP (EFI System Partition) or in an unsigned portion of the firmware update. The proposed attack method can be used to bypass the UEFI Secure Boot verified boot mechanism and hardware protection mechanisms such as Intel Boot Guard, AMD Hardware-Validated Boot, and ARM TrustZone Secure Boot.

The issue arises from the fact that firmware allows users to display specified logos and utilizes image parsing libraries that are executed at the firmware level without privilege dropping. It is noted that modern firmware includes code for parsing BMP, GIF, JPEG, PCX, and TGA formats, which contain vulnerabilities leading to buffer overflow when parsing invalid data.

Vulnerabilities have been found in firmware supplied by various hardware vendors (Intel, Acer, Lenovo) and firmware manufacturers (AMI, Insyde, Phoenix). Since the problematic code is present in reference components provided by independent firmware vendors and used as a basis for creating their firmware by various hardware manufacturers, the vulnerabilities are not specific to particular vendors and affect the entire ecosystem.

Details about the identified vulnerabilities are promised to be revealed on December 6 at the Black Hat Europe 2023 conference. The presentation will also demonstrate an exploit that allows executing arbitrary code with firmware privileges on x86 and ARM architecture systems. Initially, the vulnerabilities were discovered during analysis of Lenovo firmware built on platforms from Insyde, AMI, and Phoenix, but Intel and Acer firmware are also mentioned as potentially vulnerable.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster