LogoFAIL — an attack on UEFI firmware through the substitution of malicious logos
Researchers from Binarly have uncovered a series of vulnerabilities in the image parsing code used in UEFI firmware from various manufacturers. These vulnerabilities allow for the execution of arbitrary code during boot by placing specially crafted images in the ESP (EFI System Partition) or in parts of the firmware update that lack a valid digital signature. The proposed attack method can be used to bypass the verified boot mechanism […]
