HomeinetBlack Hat 2013 presented 2 ways to attack Windows Secure Boot...

Black Hat 2013 presented 2 ways to attack Windows 8 Secure Boot

Security researchers have discovered two ways to bypass Windows 8 's Secure Boot . The attack methods are not based on any vulnerability in Secure Boot, but rather on the way computer manufacturers have implemented the Unified Extensible Firmware Interface (UEFI) .black hat

Andrew Furtak, Oleksandr Bazhaniuk, and Yuriy Bulygin at the Black Hat 2013 in Las Vegas presented two different attack methods that can be used to bypass Secure Boot and install a UEFI bootkit, as reported by PCWorld.

One of the attack techniques relies on security holes in the device's firmware. However, in this case, exploits that can change the code responsible for implementing the Secure Boot mechanism must be implemented in kernel mode.

This makes the attack more difficult, because hackers would have to find a way to execute the code in the part of the operating system that has the most privileges.

The vulnerability has already been reported to computer manufacturers, and about a year ago, Asus released BIOS updates that fix the vulnerability, but not on all of its products. VivoBook laptops , for example, are still vulnerable.

The second method is not as limited. Hackers can exploit vulnerabilities in common applications like Microsoft Office, Java, and Adobe Flash to bypass Secure Boot.

Since the security vulnerabilities were only recently discovered and manufacturers have not released updates, experts did not provide many technical details about how the attacks are carried out.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS