Discover top-rated products and exclusive deals handpicked to make your shopping smarter, easier, and more affordable every day

New UEFI Firmware Flaw Exposes Well-liked Motherboards To Assaults

Cybersecurity specialists simply discovered a flaw in the UEFI firmware that many trendy motherboards use. The “bug” might let attackers do direct reminiscence entry (DMA) assaults on methods, which can allow unauthorized customers to realize deep and chronic entry to affected methods underneath sure circumstances, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.

To offer you context, the PC motherboard comprises low-level software program referred to as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} elements. One in every of its main safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s meant to safeguard system reminiscence. If arrange accurately, the IOMMU stops exterior gadgets from studying or writing to random components of system RAM.

Elements resembling PCIe enlargement playing cards, Thunderbolt peripherals, GPUs, and comparable {hardware} that may entry reminiscence straight with out passing by the CPU are included in DMA-capable gadgets. Malicious or compromised {hardware} can have much less of an affect as a result of these gadgets are restricted to specific reminiscence areas if the IOMMU is operational and correctly initialized.

The just lately found vulnerability is attributable to the improper manner this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, despite the fact that the IOMMU was by no means absolutely or accurately arrange, after which the working system consequently assumes that reminiscence protections are applied, despite the fact that they don’t seem to be actively enforced.

The difficulty is being tracked underneath a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options otherwise.

Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, had been the primary ones to establish the vulnerability. Vanguard, Riot’s anti-cheat system, is applied on the kernel stage and incorporates safeguards which are meant to forestall unauthorized system manipulation. Valorant could also be prevented from launching on methods which are affected by this particular flaw, as it detects an unsafe {hardware} safety state.

There may be an vital limitation to consider, despite the fact that the attainable impact could possibly be horrible: the flexibility to bodily entry the system and join a malicious PCIe or comparable system earlier than the working system boots up are stipulations for a DMA assault. Consequently, the likelihood of widespread exploitation is considerably diminished, significantly for residential customers.

Customers are being suggested to monitor updates from their motherboard producers and apply any obtainable firmware patches. Updating the UEFI firmware continues to be important to preserving system safety, significantly in mild of the continued evolution of hardware-level assaults.

Filed in Computers. Learn extra about , , , and .

Trending Merchandise

- 27% TP-Hyperlink Good WiFi 6 Router (Ar...
Original price was: $79.99.Current price is: $58.19.

TP-Hyperlink Good WiFi 6 Router (Ar...

0
Add to compare
- 31% MOFII Wireless Keyboard and Mouse C...
Original price was: $57.59.Current price is: $39.99.

MOFII Wireless Keyboard and Mouse C...

0
Add to compare
- 39% MSI MAG Forge 112R – Premium ...
Original price was: $148.48.Current price is: $89.99.

MSI MAG Forge 112R – Premium ...

0
Add to compare
- 33% Rii RK400 RGB Gaming Keyboard and M...
Original price was: $29.99.Current price is: $19.99.

Rii RK400 RGB Gaming Keyboard and M...

0
Add to compare
- 40% Lenovo V-Series V15 Business Laptop...
Original price was: $1,093.94.Current price is: $659.00.

Lenovo V-Series V15 Business Laptop...

0
Add to compare
- 35% Logitech MK345 Wireless Keyboard an...
Original price was: $61.18.Current price is: $39.99.

Logitech MK345 Wireless Keyboard an...

0
Add to compare
- 6% Lenovo Latest 15.6″” La...
Original price was: $399.87.Current price is: $375.55.

Lenovo Latest 15.6″” La...

0
Add to compare
- 42% HP 17.3″ FHD Essential Busine...
Original price was: $1,113.24.Current price is: $643.49.

HP 17.3″ FHD Essential Busine...

0
Add to compare
- 42% H602 Gaming ATX PC Case, Mid-Tower ...
Original price was: $190.28.Current price is: $109.99.

H602 Gaming ATX PC Case, Mid-Tower ...

0
Add to compare
- 31% Acer Nitro 27″ WQHD 2560 x 14...
Original price was: $289.99.Current price is: $199.99.

Acer Nitro 27″ WQHD 2560 x 14...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

ShopStellarFinds
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart