New UEFI vulnerabilities send firmware devs industry wide scrambling
Full article368 words · extracted from arstechnica.com · click to collapse
The makers of the affected UEFIs are in the process of getting updates pushed out to customers. And from there, those customers are making patches available to their customers, who usually are end users. AMI confirmed the vulnerability affects its Optio V line of firmware and said it has made patches available to its customers. AMI provided a public advisory here and customer-only ones here and here.
Microsoft, meanwhile, issued a statement that said the company was taking “appropriate action” without saying what that was. Microsoft also claimed—in error, Arce said—that exploiting the vulnerability required the attacker to first establish a malicious server on the affected network. Arce says no such requirement exists.
“An attack only needs to be able to send packets on that network,” he said. “Also, the proof of concept code which we provided to all vendors, including Microsoft, does not set up any server.”
Microsoft didn’t have a response to Arce’s analysis. Microsoft also noted the requirement of using PXE over an IPv6 network.
“As a security best practice, we recommend disabling unused boot capabilities, only using PXE or other protocols on trusted networks, and using TLS over the internet,” Microsoft officials added.
Officials with Arm Insyde and Phoenix didn’t respond or didn’t have a comment.
As noted, PixieFail isn’t something most people need to worry about. The vulnerabilities, however, are most definitely something that cloud environments and data centers should greatly care about. After all, exploits allow someone with limited network access to suddenly backdoor any server in a network the next time it reboots. Over the course of a matter of weeks, that could lead to an entire fleet of infected machines.
Out of an abundance of caution and in keeping with security in-depth principles, all end users should patch the vulnerabilities as well, but the urgency in this case is fairly relaxed. Users generally should look to their device or motherboard maker for an update.
Update: A little more than 13 hours after this post went live, Microsoft officials updated their statement to add: “If an attacker is able to capture and transmit packets on the network (this is, the ability “to serve” packets), they can pretend to be a ‘server.’”
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2024/01/new-uefi-vulnerabilities-send-firmware-devs-across-an-entire-ecosystem-scrambling/