{"id":103242,"date":"2022-02-08T09:36:38","date_gmt":"2022-02-08T07:36:38","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm"},"modified":"2022-02-08T09:36:38","modified_gmt":"2022-02-08T07:36:38","slug":"uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm","title":{"rendered":"Vulnerabilit\u00e0 nei firmware UEFI basati sul framework InsydeH2O, consentendo l'esecuzione di codice a livello SMM","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nel framework InsydeH2O, utilizzato da molti produttori per creare firmware UEFI per il proprio hardware (la realizzazione pi\u00f9 comune del UEFI BIOS), sono state identificate 23 vulnerabilit\u00e0 che consentono l'esecuzione di codice a livello SMM (System Management Mode), pi\u00f9 prioritario (Ring -2) rispetto alla modalit\u00e0 hypervisor e al livello di protezione zero, con accesso illimitato all'intera memoria. Il problema interessa i firmware UEFI utilizzati da produttori come Fujitsu, Siemens, Dell, HP, HPE, Lenovo, Microsoft, Intel e Bull Atos.    <\/p>\n<p>Per sfruttare le vulnerabilit\u00e0 \u00e8 necessario un accesso locale con privilegi di amministratore, il che rende queste problematiche interessanti come vulnerabilit\u00e0 di secondo livello, utilizzate dopo aver sfruttato altre vulnerabilit\u00e0 nel sistema o utilizzando metodi di ingegneria sociale. L'accesso a livello SMM consente l'esecuzione di codice in un livello non controllato dal sistema operativo, il che pu\u00f2 essere utilizzato per modificare i firmware e lasciarvi codice dannoso o rootkit nascosti nella SPI Flash, non identificabili dal sistema operativo, nonch\u00e9 per disabilitare la verifica durante la fase di avvio (UEFI Secure Boot, Intel BootGuard) e attacchi agli hypervisor per eludere i meccanismi di verifica dell'integrit\u00e0 degli ambienti virtuali.  <center><img decoding=\"async\" alt=\"Vulnerabilit\u00e0 nei firmware UEFI basati sul framework InsydeH2O, consentendo l&#039;esecuzione di codice a livello SMM\" src=\"\/wp-content\/uploads\/2022\/02\/dcf918bee3be0d2788f82d325cd671c7.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>Lo sfruttamento delle vulnerabilit\u00e0 pu\u00f2 essere effettuato dal sistema operativo tramite SMI handler (System Management Interrupt) non verificati, nonch\u00e9 in una fase precedente all'esecuzione del sistema operativo durante le fasi iniziali del boot o durante il risveglio da uno stato di sospensione. Tutte le vulnerabilit\u00e0 sono causate da problemi di gestione della memoria e sono suddivise in tre categorie:   <\/p>\n<ul>\n<li class=\"l\"> SMM Callout \u2014 esecuzione del proprio codice con i diritti SMM tramite il reindirizzamento dell'esecuzione dei gestori di interruzione SWSMI su codice al di fuori di SMRAM;\n<li class=\"l\"> Corruzioni di memoria che consentono all'attaccante di scrivere i propri dati in SMRAM, una speciale area di memoria isolata in cui viene eseguito codice con privilegi SMM.\n<li class=\"l\"> Corruzione di memoria nel codice eseguito a livello DXE (Driver eXecution Environment).  <\/ul>\n<p>Per dimostrare i principi dell'organizzazione di un attacco, \u00e8 stato pubblicato un esempio di exploit che consente, attraverso un attacco dal terzo o dal nullo anello di protezione, di accedere al DXE Runtime UEFI e di eseguire il proprio codice. L'exploit manipola il buffer overflow (CVE-2021-42059) nel driver UEFI DXE. Durante l'attacco, l'attaccante pu\u00f2 inserire il proprio codice nel driver DXE, che mantiene l'attivit\u00e0 anche dopo il riavvio del sistema operativo, oppure apportare modifiche all'area NVRAM nel Flash SPI. Durante l'esecuzione, il codice dell'attaccante pu\u00f2 modificare aree di memoria privilegiate, modificare i servizi EFI Runtime e influenzare il processo di avvio.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56656\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 InsydeH2O, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043c\u043d\u043e\u0433\u0438\u043c\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f\u043c\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a \u043a \u0441\u0432\u043e\u0435\u043c\u0443 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044e (\u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0451\u043d\u043d\u0430\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f UEFI BIOS), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b 23 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM (System Management Mode), \u0431\u043e\u043b\u0435\u0435 \u043f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0442\u043d\u043e\u043c (Ring -2), \u0447\u0435\u043c \u0440\u0435\u0436\u0438\u043c \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0430 \u0438 \u043d\u0443\u043b\u0435\u0432\u043e\u0435 \u043a\u043e\u043b\u044c\u0446\u043e \u0437\u0430\u0449\u0438\u0442\u044b, \u0438 \u0438\u043c\u0435\u044e\u0449\u0438\u043c \u043d\u0435\u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a\u043e \u0432\u0441\u0435\u0439 \u043f\u0430\u043c\u044f\u0442\u0438. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0435 \u0442\u0430\u043a\u0438\u043c\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f\u043c\u0438, \u043a\u0430\u043a Fujitsu, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":103243,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103242","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 InsydeH2O, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043c\u043d\u043e\u0433\u0438\u043c\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f\u043c\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a \u043a \u0441\u0432\u043e\u0435\u043c\u0443 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044e (\u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0451\u043d\u043d\u0430\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f UEFI BIOS), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b 23 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 InsydeH2O, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 InsydeH2O, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043c\u043d\u043e\u0433\u0438\u043c\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f\u043c\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a \u043a \u0441\u0432\u043e\u0435\u043c\u0443 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044e (\u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0451\u043d\u043d\u0430\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f UEFI BIOS), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b 23 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-02-08T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-02-08T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 nei firmware UEFI basati sul framework InsydeH2O che consentono di eseguire codice a livello di SMM | ProHoster","description":"Nel framework InsydeH2O, utilizzato da molti produttori per creare firmware UEFI per il proprio hardware (l'implementazione UEFI BIOS pi\u00f9 comune), sono state scoperte 23 vulnerabilit\u00e0 che consentono di eseguire codice.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 InsydeH2O, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 SMM | ProHoster","og:description":"\u0412\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 InsydeH2O, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043c\u043d\u043e\u0433\u0438\u043c\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f\u043c\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a \u043a \u0441\u0432\u043e\u0435\u043c\u0443 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044e (\u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0451\u043d\u043d\u0430\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f UEFI BIOS), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b 23 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-uefi-proshivkah-na-baze-frejmvorka-insydeh2o-pozvolyayushhie-vypolnit-kod-na-urovne-smm","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-02-08T07:36:38+00:00","article:modified_time":"2022-02-08T07:36:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103242","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-02-08 07:37:23","updated":"2022-09-30 03:48:48","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=103242"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103242\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/103243"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=103242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=103242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=103242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}