{"id":105506,"date":"2022-11-09T03:36:39","date_gmt":"2022-11-09T01:36:39","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-proshivkah-uefi-pozvolyayushhaya-vypolnit-kod-na-urovne-smm"},"modified":"2022-11-09T03:36:39","modified_gmt":"2022-11-09T01:36:39","slug":"uyazvimost-v-proshivkah-uefi-pozvolyayushhaya-vypolnit-kod-na-urovne-smm","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-proshivkah-uefi-pozvolyayushhaya-vypolnit-kod-na-urovne-smm","title":{"rendered":"Vulnerability in UEFI firmware allowing code execution at the SMM level.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Information about the vulnerability (CVE-2021-33164) in UEFI firmware has been revealed, allowing code execution at the SMM (System Management Mode) level, which is more privileged than the hypervisor mode and zero protection ring, providing unrestricted access to all system memory. The vulnerability, code-named RingHopper, is related to the possibility of a timing attack using DMA (Direct Memory Access) to corrupt memory in code executed at the SMM level. The presence of the vulnerability has been confirmed in firmware from Intel, Dell, and Insyde Software (it's claimed that the issue affects 8 manufacturers, but the remaining 5 have not yet been disclosed). AMD, Phoenix, and Toshiba firmware are not vulnerable to this issue.    <\/p>\n<p>Exploitation of vulnerabilities can be performed from the operating system using vulnerable SMI (System Management Interrupt) handlers, access to which requires administrative privileges. An attack can also be conducted with physical access at an early boot stage, before the operating system is initialized. To mitigate the issue, Linux users are recommended to update the firmware using the LVFS (Linux Vendor Firmware Service) with the tool fwupdmgr (fwupdmgr get-updates; fwupdmgr update) from the fwupd package.      <\/p>\n<p>The requirement for administrative privileges to carry out an attack limits the danger of the issue but does not prevent its use as a second-tier vulnerability to maintain presence after exploiting other vulnerabilities in the system or applying social engineering methods. Access to SMM (Ring -2) allows code execution at a level not controlled by the operating system, which can be used to modify firmware and place hidden malicious code or rootkits in SPI Flash that are not detectable from the operating system, as well as to disable verification during the boot phase (UEFI Secure Boot, Intel BootGuard) and to attack hypervisors to bypass integrity checking mechanisms for virtual environments.       <\/p>\n<p>The issue is caused by a race condition in the SMI (System Management Interrupt) handler, which occurs at the moment between access verification and calling SMRAM. To determine the optimal moment between checking the status and using the verification result, analysis through side channels using DMA can be employed. As a result, due to the asynchronous nature of access to SMRAM via DMA, an attacker can identify the required moment and overwrite the contents of SMRAM by using DMA to bypass the SMI handler API. Processors that support Intel-VT and Intel VT-d mechanisms include protection against DMA attacks, based on the use of IOMMU (Input-Output Memory Management Unit), but this protection is effective for blocking hardware DMA attacks executed by prepared attacker devices, and does not protect against attacks via SMI handlers.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58075\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2021-33164) \u0432 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 UEFI, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM (System Management Mode), \u0431\u043e\u043b\u0435\u0435 \u043f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0442\u043d\u043e\u043c, \u0447\u0435\u043c \u0440\u0435\u0436\u0438\u043c \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0430 \u0438 \u043d\u0443\u043b\u0435\u0432\u043e\u0435 \u043a\u043e\u043b\u044c\u0446\u043e \u0437\u0430\u0449\u0438\u0442\u044b, \u0438 \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u043d\u0435\u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a\u043e \u0432\u0441\u0435\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f RingHopper, \u0441\u0432\u044f\u0437\u0430\u043d\u0430 \u0441 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c\u044e \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043f\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 DMA (Direct Memory Access) \u0434\u043b\u044f \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-105506","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2021-33164) \u0432 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 UEFI, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM (System Management Mode), \u0431\u043e\u043b\u0435\u0435 \u043f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0442\u043d\u043e\u043c, \u0447\u0435\u043c \u0440\u0435\u0436\u0438\u043c \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0430 \u0438 \u043d\u0443\u043b\u0435\u0432\u043e\u0435 \u043a\u043e\u043b\u044c\u0446\u043e \u0437\u0430\u0449\u0438\u0442\u044b, \u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-proshivkah-uefi-pozvolyayushhaya-vypolnit-kod-na-urovne-smm\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 UEFI, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2021-33164) \u0432 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 UEFI, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM (System Management Mode), \u0431\u043e\u043b\u0435\u0435 \u043f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0442\u043d\u043e\u043c, \u0447\u0435\u043c \u0440\u0435\u0436\u0438\u043c \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0430 \u0438 \u043d\u0443\u043b\u0435\u0432\u043e\u0435 \u043a\u043e\u043b\u044c\u0446\u043e \u0437\u0430\u0449\u0438\u0442\u044b, \u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-proshivkah-uefi-pozvolyayushhaya-vypolnit-kod-na-urovne-smm\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-11-09T01:36:39+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-11-09T01:36:39+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerability in UEFI firmware allowing code execution at the SMM level | ProHoster","description":"Information about the vulnerability (CVE-2021-33164) in UEFI firmware has been revealed, allowing code execution at the SMM (System Management Mode) level, which is more privileged than the hypervisor mode and ring zero protection.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-proshivkah-uefi-pozvolyayushhaya-vypolnit-kod-na-urovne-smm","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 UEFI, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM | ProHoster","og:description":"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2021-33164) \u0432 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 UEFI, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM (System Management Mode), \u0431\u043e\u043b\u0435\u0435 \u043f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0442\u043d\u043e\u043c, \u0447\u0435\u043c \u0440\u0435\u0436\u0438\u043c \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0430 \u0438 \u043d\u0443\u043b\u0435\u0432\u043e\u0435 \u043a\u043e\u043b\u044c\u0446\u043e \u0437\u0430\u0449\u0438\u0442\u044b, \u0438.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-proshivkah-uefi-pozvolyayushhaya-vypolnit-kod-na-urovne-smm","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-11-09T01:36:39+00:00","article:modified_time":"2022-11-09T01:36:39+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/105506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=105506"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/105506\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=105506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=105506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=105506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}