Hidden Firmware Backdoor Found in Gigabyte Motherboards
Via The Hacker News
The Story
Firmware security firm Eclypsium disclosed in May 2023 a hidden mechanism in the UEFI firmware of Gigabyte motherboards that effectively functions as a backdoor, affecting roughly 364 system models and an estimated 7 million devices.
The firmware drops a Windows executable to disk during the boot process and runs it as an update service, which then downloads and executes payloads from Gigabyte's update servers over unencrypted HTTP connections.
That insecure design leaves machines open to man in the middle attacks, including interception through compromised routers.
Eclypsium senior vice president John Loucaides noted that only the intention of the author distinguishes this sort of vulnerability from a malicious backdoor.
The mechanism relies on Windows Platform Binary Table, a legitimate UEFI feature that lets vendors install auto update applications, but Gigabyte implemented it without adequate security controls.
Because the code lives in motherboard firmware, malware planted through it can persist even after an operating system reinstall or a full drive wipe.
Gigabyte responded with firmware updates that add signature verification and limit privileged access during boot.
The firmware drops a Windows executable to disk during the boot process and runs it as an update service, which then downloads and executes payloads from Gigabyte's update servers over unencrypted HTTP connections.
That insecure design leaves machines open to man in the middle attacks, including interception through compromised routers.
Eclypsium senior vice president John Loucaides noted that only the intention of the author distinguishes this sort of vulnerability from a malicious backdoor.
The mechanism relies on Windows Platform Binary Table, a legitimate UEFI feature that lets vendors install auto update applications, but Gigabyte implemented it without adequate security controls.
Because the code lives in motherboard firmware, malware planted through it can persist even after an operating system reinstall or a full drive wipe.
Gigabyte responded with firmware updates that add signature verification and limit privileged access during boot.
Go Deeper
Read the original reporting at The Hacker News.
Read Full Story at The Hacker News →