Most modern motherboards support firmware write protection to prevent unwanted BIOS flashes, but a vulnerability in many UEFI firmware implementations could accidentally disable such protection. A new warning posted by Carnegie Mellon University's CERT says that when many x86-based systems wake from sleep, they fail to enable that write protection .
The security hole opens when an affected system goes to sleep and then wakes up. Many Intel-based x86 systems use a specific flag stored in a BIOS register that controls write protection. When the bit is turned on, the BIOS is write-protected—but that bit is turned off by default. Every time a PC resets, this register is also reset to the default state, and it's up to the BIOS to set it correctly. When a PC sleeps, the wake process is treated as a hardware reset, so the register resets in turn. Many BIOS implementations don't flip the write-protect bit again, so after a sleep-wake cycle, write protection is disabled.
CERT lists several vendors who may be affected, including Dell, Lenovo, and Apple, and also lists BIOS vendors like American Megatrends and Phoenix, whose BIOS implementations are found in many other systems. Apple and Dell have confirmed that at least some of their systems are affected. In response, Apple has released an EFI security update, and Dell has provided CERT with a list of affected systems. Dell customers should visit the company's support site to get their system's latest BIOS.
Amid the torrent of vulnerabilities uncovered by the Hacking Team leaks, Trend Micro warned of the gray-hat developer's UEFI rootkit, which could infect motherboards with a nasty bug. One of Trend Micro's suggestions is to make sure that one's BIOS is write-protected, but for systems affected by this sleep-wake flaw, write-protection wouldn't be enough. Another of the anti-virus maker's suggestions is to install any new BIOS with any security-related updates that might be available from your vendor. We think it'd wise to visit your motherboard vendor's support site and look for updates.
|1. BIF - $340||2. Ryu Connor - $250||3. mbutrovich - $250|
|4. YetAnotherGeek2 - $200||5. End User - $150||6. Captain Ned - $100|
|7. Anonymous Gerbil - $100||8. Bill Door - $100||9. ericfulmer - $100|
|10. dkanter - $100|
|Thermaltake revs up Engine 27 low-profile CPU cooler||7|
|Deals of the week: cheap mobos and a GTX 950||2|
|Logitech C922 Pro Stream webcam dispenses with green screens||11|
|MSI 100-series BIOS updates show Kaby Lake drops into LGA 1151||5|
|Razer revamps Kraken headsets with big drivers and metal bodies||5|
|Corsair Vengeance LED RAM family now sings the blues||4|
|Adata XPG SX8000 SSD has game libraries in mind||30|
|Amazon powers up Fire TV Stick with quad-core SoC||17|
|Cat5e and Cat6 cables get a 5Gbps speed boost||62|