Discover unbeatable deals on top-rated products — shop smart, save big, and make every day a savvy shopping day!

New UEFI Firmware Flaw Exposes In style Motherboards To Assaults

Cybersecurity specialists simply discovered a flaw in the UEFI firmware that many trendy motherboards use. The “bug” might let attackers do direct reminiscence entry (DMA) assaults on methods, which can allow unauthorized customers to realize deep and chronic entry to affected methods underneath sure situations, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.

To provide you context, the PC motherboard comprises low-level software program referred to as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} parts. Certainly one of its major safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s supposed to safeguard system reminiscence. If arrange appropriately, the IOMMU stops exterior gadgets from studying or writing to random components of system RAM.

Elements akin to PCIe enlargement playing cards, Thunderbolt peripherals, GPUs, and comparable {hardware} that may entry reminiscence immediately with out passing by means of the CPU are included in DMA-capable gadgets. Malicious or compromised {hardware} can have much less of an influence as a result of these gadgets are restricted to specific reminiscence areas if the IOMMU is operational and correctly initialized.

The just lately found vulnerability is attributable to the fallacious approach this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, although the IOMMU was by no means absolutely or appropriately arrange, after which the working system consequently assumes that reminiscence protections are carried out, although they aren’t actively enforced.

The difficulty is being tracked underneath a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options in another way.

Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, had been the primary ones to determine the vulnerability. Vanguard, Riot’s anti-cheat system, is carried out on the kernel degree and incorporates safeguards which can be supposed to stop unauthorized system manipulation. Valorant could also be prevented from launching on methods which can be affected by this particular flaw, as it detects an unsafe {hardware} safety state.

There’s an essential limitation to consider, although the attainable impact might be horrible: the flexibility to bodily entry the system and join a malicious PCIe or comparable gadget earlier than the working system boots up are stipulations for a DMA assault. Consequently, the likelihood of widespread exploitation is considerably diminished, notably for residential customers.

Customers are being suggested to monitor updates from their motherboard producers and apply any out there firmware patches. Updating the UEFI firmware remains to be important to preserving system safety, notably in mild of the continued evolution of hardware-level assaults.

Filed in Computers. Learn extra about , , , and .

Trending Merchandise

- 26% CORSAIR 3500X ARGB Mid-Tower ATX PC...
Original price was: $148.49.Current price is: $109.99.

CORSAIR 3500X ARGB Mid-Tower ATX PC...

0
Add to compare
- 7% Acer Aspire 3 A315-24P-R7VH Slim La...
Original price was: $321.99.Current price is: $299.99.

Acer Aspire 3 A315-24P-R7VH Slim La...

0
Add to compare
- 34% Logitech Wave Keys MK670 Combo, Wi-...
Original price was: $121.58.Current price is: $79.99.

Logitech Wave Keys MK670 Combo, Wi-...

0
Add to compare
- 24% HP 330 Wi-fi Keyboard and Mouse Com...
Original price was: $32.99.Current price is: $24.99.

HP 330 Wi-fi Keyboard and Mouse Com...

0
Add to compare
- 33% CHONCHOW LED Keyboard and Mouse, 10...
Original price was: $29.99.Current price is: $19.99.

CHONCHOW LED Keyboard and Mouse, 10...

0
Add to compare
- 34% SAMSUNG 34″ ViewFinity S50GC ...
Original price was: $349.99.Current price is: $229.99.

SAMSUNG 34″ ViewFinity S50GC ...

0
Add to compare
- 28% Cudy TR3000 Pocket-Sized Wi-Fi 6 Wi...
Original price was: $124.06.Current price is: $89.90.

Cudy TR3000 Pocket-Sized Wi-Fi 6 Wi...

0
Add to compare
- 33% KEDIERS White PC CASE ATX 5 PWM ARG...
Original price was: $138.56.Current price is: $92.99.

KEDIERS White PC CASE ATX 5 PWM ARG...

0
Add to compare
- 8% Nimo 15.6 FHD Pupil Laptop computer...
Original price was: $399.99.Current price is: $369.99.

Nimo 15.6 FHD Pupil Laptop computer...

0
Add to compare
- 29% SAMSUNG 27-Inch S43GC Sequence Ente...
Original price was: $209.99.Current price is: $149.99.

SAMSUNG 27-Inch S43GC Sequence Ente...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

DailySavvyFinds
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart