A flaw discovered in the unified extensible firmware interface (UEFI) of some systems allows an attacker to bypass Secure Boot, the security standard used in the latest versions of Windows to check the legitimacy of software loading at startup.
According to a bulletin from Carnegie Mellon University's Computer Emergency Response Team (CERT), some UEFI systems do not restrict access to the boot script used by the EFI S3 Resume Boot Path, which could allow a local attacker to bypass write protections enforced by the firmware.
In addition to bypassing Secure Boot, another risk that exists is that the platform software can be replaced with a different one that allows unsigned software to run during the system boot process.
The implications of this flaw are very serious because the startup script is deployed before any security mechanism is initiated, meaning that the attacker can gain persistent access to the system regardless of the owner's efforts and means of protection.
“The boot script is launched quite early, when other important platform security mechanisms have not yet been configured. For example, BIOS_CNTL, which helps protect the firmware, is not locked. TSEGMB, which protects SMRAM from DMA, is also unlocked,” said Rafal Wojtczuk of Bromium and Corey Kallenberg of MITRE. Rafal Wojtczuk and Corey Kallenberg are the researchers who discovered the UEFI vulnerability.
