Discover the latest trends and best products, all in one place, at prices that make smart shopping simple

New UEFI Firmware Flaw Exposes Common Motherboards To Assaults

Cybersecurity consultants simply discovered a flaw in the UEFI firmware that many fashionable motherboards use. The “bug” might let attackers do direct reminiscence entry (DMA) assaults on programs, which can allow unauthorized customers to achieve deep and protracted entry to affected programs underneath sure situations, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.

To provide you context, the PC motherboard accommodates low-level software program known as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} elements. One in every of its main safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s meant to safeguard system reminiscence. If arrange accurately, the IOMMU stops exterior units from studying or writing to random elements of system RAM.

Parts reminiscent of PCIe enlargement playing cards, Thunderbolt peripherals, GPUs, and comparable {hardware} that may entry reminiscence instantly with out passing by means of the CPU are included in DMA-capable units. Malicious or compromised {hardware} can have much less of an impression as a result of these units are restricted to explicit reminiscence areas if the IOMMU is operational and correctly initialized.

The lately found vulnerability is attributable to the mistaken method this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, regardless that the IOMMU was by no means absolutely or accurately arrange, after which the working system consequently assumes that reminiscence protections are carried out, regardless that they aren’t actively enforced.

The difficulty is being tracked underneath a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options in another way.

Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, have been the primary ones to determine the vulnerability. Vanguard, Riot’s anti-cheat system, is carried out on the kernel stage and incorporates safeguards which can be meant to stop unauthorized system manipulation. Valorant could also be prevented from launching on programs which can be affected by this particular flaw, as it detects an unsafe {hardware} safety state.

There may be an essential limitation to consider, regardless that the attainable impact might be horrible: the power to bodily entry the system and join a malicious PCIe or comparable gadget earlier than the working system boots up are stipulations for a DMA assault. Consequently, the chance of widespread exploitation is considerably diminished, notably for residential customers.

Customers are being suggested to monitor updates from their motherboard producers and apply any obtainable firmware patches. Updating the UEFI firmware remains to be important to preserving system safety, notably in gentle of the continued evolution of hardware-level assaults.

Filed in Computers. Learn extra about , , , and .

Trending Merchandise

- 14% Logitech MK825 Performance Wireless...
Original price was: $69.99.Current price is: $59.90.

Logitech MK825 Performance Wireless...

0
Add to compare
- 37% Acer SH242Y Ebmihx 23.8″ FHD ...
Original price was: $157.98.Current price is: $99.99.

Acer SH242Y Ebmihx 23.8″ FHD ...

0
Add to compare
- 44% Logitech MK345 Wireless Keyboard an...
Original price was: $70.78.Current price is: $39.99.

Logitech MK345 Wireless Keyboard an...

0
Add to compare
- 24% GAMDIAS ATX Mid Tower Gaming Pc PC ...
Original price was: $78.59.Current price is: $59.99.

GAMDIAS ATX Mid Tower Gaming Pc PC ...

0
Add to compare
- 33% Logitech Signature MK650 Combo for ...
Original price was: $104.29.Current price is: $69.99.

Logitech Signature MK650 Combo for ...

0
Add to compare
- 44% NZXT H9 Move Twin-Chamber ATX Mid-T...
Original price was: $287.95.Current price is: $159.97.

NZXT H9 Move Twin-Chamber ATX Mid-T...

0
Add to compare
- 24% Acer KC242Y Hbi 23.8″ Full HD...
Original price was: $117.99.Current price is: $89.99.

Acer KC242Y Hbi 23.8″ Full HD...

0
Add to compare
- 28% ASUS RT-AX5400 Dual Band WiFi 6 Ext...
Original price was: $179.99.Current price is: $129.99.

ASUS RT-AX5400 Dual Band WiFi 6 Ext...

0
Add to compare
- 29% Lenovo Ideapad Laptop Touchscreen 1...
Original price was: $774.09.Current price is: $549.00.

Lenovo Ideapad Laptop Touchscreen 1...

0
Add to compare
- 43% Wireless Keyboard and Mouse Combo, ...
Original price was: $38.92.Current price is: $21.99.

Wireless Keyboard and Mouse Combo, ...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

ShopTopTrends
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart