{"id":103242,"date":"2022-02-08T09:36:38","date_gmt":"2022-02-08T07:36:38","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm"},"modified":"2022-02-08T09:36:38","modified_gmt":"2022-02-08T07:36:38","slug":"uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm","title":{"rendered":"Vulnerabilidades en firmware UEFI basadas en el marco InsydeH2O permiten la ejecuci\u00f3n de c\u00f3digo en modo SMM","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>En el marco de InsydeH2O, utilizado por muchos fabricantes para crear firmware UEFI para su hardware (la implementaci\u00f3n m\u00e1s com\u00fan de UEFI BIOS), se han identificado 23 vulnerabilidades que permiten ejecutar c\u00f3digo en el nivel SMM (Modo de Gesti\u00f3n del Sistema), que tiene una prioridad mayor (Ring -2) que el modo hipervisor y el anillo cero de protecci\u00f3n, y que tiene acceso ilimitado a toda la memoria. El problema afecta a los firmware UEFI utilizados por fabricantes como Fujitsu, Siemens, Dell, HP, HPE, Lenovo, Microsoft, Intel y Bull Atos.    <\/p>\n<p>Para explotar las vulnerabilidades se requiere acceso local con privilegios de administrador, lo que hace que estos problemas sean relevantes como vulnerabilidades de segundo nivel, que se utilizan despu\u00e9s de la explotaci\u00f3n de otras vulnerabilidades en el sistema o mediante m\u00e9todos de ingenier\u00eda social. El acceso en el nivel SMM permite ejecutar c\u00f3digo en un nivel que no est\u00e1 bajo el control del sistema operativo, lo que puede ser utilizado para modificar firmware y dejar c\u00f3digo malicioso oculto o rootkits en la SPI Flash, indetectables desde el sistema operativo, as\u00ed como para desactivar la verificaci\u00f3n en la etapa de arranque (UEFI Secure Boot, Intel BootGuard) y atacar hipervisores para evadir los mecanismos de verificaci\u00f3n de la integridad de los entornos virtuales.  <center><img decoding=\"async\" alt=\"Vulnerabilidades en firmware UEFI basadas en el marco InsydeH2O permiten la ejecuci\u00f3n de c\u00f3digo en modo SMM\" src=\"\/wp-content\/uploads\/2022\/02\/dcf918bee3be0d2788f82d325cd671c7.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>La explotaci\u00f3n de las vulnerabilidades se puede realizar desde el sistema operativo mediante controladores SMI (Interrupci\u00f3n de Gesti\u00f3n del Sistema) no verificados, as\u00ed como en la etapa previa a la ejecuci\u00f3n del sistema operativo durante las etapas iniciales de arranque o al salir del modo de suspensi\u00f3n. Todas las vulnerabilidades son causadas por problemas de manejo de memoria y se dividen en tres categor\u00edas:   <\/p>\n<ul>\n<li class=\"l\"> SMM Callout  \u2014 ejecuci\u00f3n de su propio c\u00f3digo con privilegios SMM a trav\u00e9s de la redirecci\u00f3n de los manejadores de interrupciones SWSMI a c\u00f3digo fuera de SMRAM;\n<li class=\"l\"> Da\u00f1os en la memoria que permiten al atacante escribir sus datos en SMRAM, un \u00e1rea de memoria aislada especial donde se ejecuta c\u00f3digo con privilegios SMM.\n<li class=\"l\"> Da\u00f1o en la memoria en el c\u00f3digo que se ejecuta en el nivel DXE (Entorno de Ejecuci\u00f3n de Controladores).  <\/ul>\n<p>Para demostrar los principios de organizaci\u00f3n de un ataque, se ha publicado un ejemplo de exploit que permite, a trav\u00e9s de un ataque desde el tercer o el cero anillo de defensa, obtener acceso al UEFI Runtime DXE y ejecutar su propio c\u00f3digo. El exploit manipula un desbordamiento de pila (CVE-2021-42059) en el controlador UEFI DXE. Durante el ataque, un atacante puede insertar su c\u00f3digo en un controlador DXE, manteniendo la actividad tras reiniciar el sistema operativo, o alterar la regi\u00f3n NVRAM en SPI Flash. Durante la ejecuci\u00f3n, el c\u00f3digo del atacante puede modificar \u00e1reas privilegiadas de la memoria, modificar los servicios EFI Runtime e influir en el proceso de arranque.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56656\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 InsydeH2O, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043c\u043d\u043e\u0433\u0438\u043c\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f\u043c\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a \u043a \u0441\u0432\u043e\u0435\u043c\u0443 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044e (\u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0451\u043d\u043d\u0430\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f UEFI BIOS), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b 23 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM (System Management Mode), \u0431\u043e\u043b\u0435\u0435 \u043f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0442\u043d\u043e\u043c (Ring -2), \u0447\u0435\u043c \u0440\u0435\u0436\u0438\u043c \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0430 \u0438 \u043d\u0443\u043b\u0435\u0432\u043e\u0435 \u043a\u043e\u043b\u044c\u0446\u043e \u0437\u0430\u0449\u0438\u0442\u044b, \u0438 \u0438\u043c\u0435\u044e\u0449\u0438\u043c \u043d\u0435\u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a\u043e \u0432\u0441\u0435\u0439 \u043f\u0430\u043c\u044f\u0442\u0438. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0435 \u0442\u0430\u043a\u0438\u043c\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f\u043c\u0438, \u043a\u0430\u043a Fujitsu, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":103243,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103242","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 InsydeH2O, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043c\u043d\u043e\u0433\u0438\u043c\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f\u043c\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a \u043a \u0441\u0432\u043e\u0435\u043c\u0443 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044e (\u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0451\u043d\u043d\u0430\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f UEFI BIOS), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b 23 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 InsydeH2O, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 InsydeH2O, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043c\u043d\u043e\u0433\u0438\u043c\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f\u043c\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a \u043a \u0441\u0432\u043e\u0435\u043c\u0443 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044e (\u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0451\u043d\u043d\u0430\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f UEFI BIOS), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b 23 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-02-08T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-02-08T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidades en los firmwares UEFI basados en el marco InsydeH2O que permiten la ejecuci\u00f3n de c\u00f3digo a nivel SMM | ProHoster","description":"En el marco InsydeH2O, utilizado por muchos fabricantes para crear firmware UEFI para su hardware (la implementaci\u00f3n de UEFI BIOS m\u00e1s com\u00fan), se han identificado 23 vulnerabilidades que permiten la ejecuci\u00f3n de c\u00f3digo.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 InsydeH2O, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM | ProHoster","og:description":"\u0412\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 InsydeH2O, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043c\u043d\u043e\u0433\u0438\u043c\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f\u043c\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a \u043a \u0441\u0432\u043e\u0435\u043c\u0443 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044e (\u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0451\u043d\u043d\u0430\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f UEFI BIOS), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b 23 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-02-08T07:36:38+00:00","article:modified_time":"2022-02-08T07:36:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103242","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-02-08 07:37:23","updated":"2022-09-30 03:48:48","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/103242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=103242"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/103242\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media\/103243"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=103242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=103242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=103242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}