Discover unbeatable deals on the best products—carefully selected, budget-friendly, and delivered with trust

New UEFI Firmware Flaw Exposes Common Motherboards To Assaults

Cybersecurity consultants simply discovered a flaw in the UEFI firmware that many trendy motherboards use. The “bug” might let attackers do direct reminiscence entry (DMA) assaults on methods, which can allow unauthorized customers to realize deep and chronic entry to affected methods beneath sure circumstances, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.

To offer you context, the PC motherboard comprises low-level software program known as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} parts. Considered one of its main safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s meant to safeguard system reminiscence. If arrange appropriately, the IOMMU stops exterior units from studying or writing to random components of system RAM.

Parts similar to PCIe enlargement playing cards, Thunderbolt peripherals, GPUs, and related {hardware} that may entry reminiscence immediately with out passing by the CPU are included in DMA-capable units. Malicious or compromised {hardware} can have much less of an influence as a result of these units are restricted to explicit reminiscence areas if the IOMMU is operational and correctly initialized.

The just lately found vulnerability is attributable to the fallacious approach this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, despite the fact that the IOMMU was by no means absolutely or appropriately arrange, after which the working system consequently assumes that reminiscence protections are applied, despite the fact that they aren’t actively enforced.

The problem is being tracked beneath a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options in another way.

Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, had been the primary ones to establish the vulnerability. Vanguard, Riot’s anti-cheat system, is applied on the kernel stage and incorporates safeguards which can be meant to forestall unauthorized system manipulation. Valorant could also be prevented from launching on methods which can be affected by this particular flaw, as it detects an unsafe {hardware} safety state.

There may be an essential limitation to consider, despite the fact that the attainable impact might be horrible: the flexibility to bodily entry the system and join a malicious PCIe or related gadget earlier than the working system boots up are stipulations for a DMA assault. Consequently, the chance of widespread exploitation is considerably diminished, significantly for residential customers.

Customers are being suggested to monitor updates from their motherboard producers and apply any accessible firmware patches. Updating the UEFI firmware remains to be important to preserving system safety, significantly in mild of the continued evolution of hardware-level assaults.

Filed in Computers. Learn extra about , , , and .

Trending Merchandise

- 29% Lenovo Latest 15.6″ Laptop co...
Original price was: $769.99.Current price is: $549.99.

Lenovo Latest 15.6″ Laptop co...

0
Add to compare
- 11% Thermaltake V250 Motherboard Sync A...
Original price was: $89.99.Current price is: $79.99.

Thermaltake V250 Motherboard Sync A...

0
Add to compare
- 20% Dell KM3322W Keyboard and Mouse
Original price was: $24.99.Current price is: $19.99.

Dell KM3322W Keyboard and Mouse

0
Add to compare
- 20% Sceptre Curved 24-inch Gaming Monit...
Original price was: $99.97.Current price is: $79.97.

Sceptre Curved 24-inch Gaming Monit...

0
Add to compare
- 30% HP 27h Full HD Monitor – Diag...
Original price was: $229.99.Current price is: $159.99.

HP 27h Full HD Monitor – Diag...

0
Add to compare
- 18% Wi-fi Keyboard and Mouse Combo &#82...
Original price was: $39.99.Current price is: $32.99.

Wi-fi Keyboard and Mouse Combo R...

0
Add to compare
- 39% ASUS 27 Inch Monitor – 1080P,...
Original price was: $195.16.Current price is: $119.00.

ASUS 27 Inch Monitor – 1080P,...

0
Add to compare
- 19% Lenovo V14 Gen 3 Enterprise Laptop ...
Original price was: $739.00.Current price is: $599.00.

Lenovo V14 Gen 3 Enterprise Laptop ...

0
Add to compare
- 34% Amazon Fundamentals – 27 Inch...
Original price was: $181.18.Current price is: $119.99.

Amazon Fundamentals – 27 Inch...

0
Add to compare
- 37% View 270 Plus TG ARGB Black Mid Tow...
Original price was: $127.98.Current price is: $79.99.

View 270 Plus TG ARGB Black Mid Tow...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

TheBudgetPlugg
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart