Trill News

Winning isn't everything, but wanting to win is. — Vince Lombardi
STEM

Hidden Firmware Backdoor Found in Gigabyte Motherboards

Hidden Firmware Backdoor Found in Gigabyte Motherboards
Computer motherboard 11 by Kurt Kaiser (CC0)
Firmware security firm Eclypsium disclosed in May 2023 a hidden mechanism in the UEFI firmware of Gigabyte motherboards that effectively functions as a backdoor, affecting roughly 364 system models and an estimated 7 million devices.

The firmware drops a Windows executable to disk during the boot process and runs it as an update service, which then downloads and executes payloads from Gigabyte's update servers over unencrypted HTTP connections.

That insecure design leaves machines open to man in the middle attacks, including interception through compromised routers.

Eclypsium senior vice president John Loucaides noted that only the intention of the author distinguishes this sort of vulnerability from a malicious backdoor.

The mechanism relies on Windows Platform Binary Table, a legitimate UEFI feature that lets vendors install auto update applications, but Gigabyte implemented it without adequate security controls.

Because the code lives in motherboard firmware, malware planted through it can persist even after an operating system reinstall or a full drive wipe.

Gigabyte responded with firmware updates that add signature verification and limit privileged access during boot.
The 2023 backdoor was a design choice; Gigabyte's next firmware problem was plain bugs. In July 2025 CERT/CC published four System Management Mode flaws, each scored 8.2, letting an attacker with kernel access plant an implant beneath Secure Boot on roughly 240 board models on older Intel chipsets, per BleepingComputer. Gigabyte shipped fixes from June 2025 but declared Z370 boards end of life, so those owners get nothing. Binarly's chief executive blamed AMI for disclosing the bugs silently to paying customers under NDA. Microsoft's 2011 Secure Boot certificates expired June 24 and 27, 2026, and Microsoft says machines without the 2023 replacements stop receiving boot level mitigations, with the Windows Production PCA following on October 19, 2026.

Read the original reporting at The Hacker News.

Read Full Story at The Hacker News →

FIND A BOOK ON BOOKSHOP.ORG