HomeSecurityUEFI Zero-Day Flaw Disables Security Features

UEFI Zero-Day Flaw Disables Security Features

Researcher Dmytro Oleksiuk has published details of the ThinkPwn flaw, a UEFI Zero-Day that can be exploited by hackers to disable security features.

Once again, IT giant Lenovo is in the spotlight, as some of the company's products and some other computer vendors are affected by a UEFI vulnerability, codenamed ThinkPwn, which can be exploited by an attacker to disable firmware write-protection.

UEFI Zero-Day Flaw Disables Security Features

The discovery was made by Dmytro Oleksiuk who published a Lenovo ThinkPad System Management Mode arbitrary code execution 0day exploit on GitHub

According to Oleksiuk, the ThinkPwn vulnerability resides in Lenovo's System Management Mode (SMM) code of UEFI, and he explains that a hacker can exploit this zero-day flaw to disable flash write protection and infect the firmware. The attacker can also disable the Secure Boot feature and bypass security features , such as Device Guard or Credential Guard.

Oleksiuk believes that this faulty code was inherited from Intel, and specifically, SystemSmmRuntimeRt copied the code in question from Intel.

Lenovo has issued a security advisory to inform customers that its experts are investigating the issue. The company highlighted the ThinkPwn vulnerability results from the use of code by at least three BIOS vendors. These BIOS vendors take code provided by chip vendors, such as AMD and Intel, and develop their own customized versions.

Of course, rumors are circulating on the internet talking about a possibility that this ThinkPwn vulnerability may be a deliberate backdoor.

El Reg stated in a tweet shared with Oleksiuk's followers that the ThinkPwn vulnerability in question also affects 2010-era HP Pavillion machines.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS