Your computer usually gets to work and spends time doing this before loading Windows. This phase is called UEFI, and recently a new vulnerability has been found during this stage of the start cycle. It was found that this vulnerability affects Gigabyte, MSI, ASUS, and ASRock brand motherboards, which some of us may be using now as part of our day-to-day lives.
Many of the games that have advanced anti-cheat capabilities will not allow gameplay on any system susceptible to this vulnerability, until the user performs a firmware update. This is evidence of how critical this issue is.
What’s The Issue In Simple Terms?
Attackers can use this vulnerability, commonly referred to as DMA (Direct Memory Access). This permits an external device to communicate directly with your system’s memory without first contacting the CPU for authorization. This is done to invade the computer’s operating system prior to installing their attack tools and gaining access to the system operating environment.How Does This Present Danger?
Under normal operating conditions, a technology called IOMMU provides a level of protection from unsafe devices accessing the system memory. At this point in the start-up cycle, on affected systems, IOMMU does not operate fully until the system has finished its booting sequence, leaving an exposed time for:- Memory is unprotected.
- An external device can intercept sensitive information stored in memory.
- Malicious software may be installed to the computer prior to the completion of Windows boot-up.
Who Discovered This Problem?
While researching the latest protection solutions for data integrity against threat actors, the security experts found this vulnerability. They contacted the motherboard manufacturers and provided them with adequate information about the vulnerability so they could develop a fix.Many of the games that have advanced anti-cheat capabilities will not allow gameplay on any system susceptible to this vulnerability, until the user performs a firmware update. This is evidence of how critical this issue is.
What Actions Should You Take?
I would recommend the following:- Visit the website of the motherboard manufacturer
- Look for the latest BIOS/UEFI update on the site
- Install the BIOS/UEFI update by following the instructions very closely
- Always back up your files prior to an update