Vulnerability in UEFI firmware allowing code execution at the SMM level.
Information has been disclosed about a vulnerability (CVE-2021-33164) in UEFI firmware that allows code execution at the SMM (System Management Mode) level, which has higher priority than the hypervisor mode and ring 0 protection, providing unrestricted access to all system memory. The vulnerability, codenamed RingHopper, is associated with the possibility of conducting a timing attack using DMA (Direct Memory Access) to compromise […]
