More than 290 MSI motherboards are reportedly vulnerable to a default UEFI Secure Boot setting that allows any OS image to boot without signature verification. This means that an operating system can run even if its signatures are missing or incorrect!
This discovery comes from a Polish security researcher named Dawid Potocki, who claims that he received no response despite his attempts to contact MSI and inform them of the issue.
According to Potocki, the issue affects several Intel and AMD-based MSI motherboards that use a new firmware version.
See also: CircleCi: Hacked via info-stealing malware on employee's laptop

UEFI Secure Boot
Secure Boot is a security feature built into the firmware of UEFI motherboards that ensures that only trusted (signed) software can be executed during the boot process.
To ensure the security of boot loaders, OS kernels, and other critical system components, Secure Boot leverages PKI (public key infrastructure) to verify all software at every device boot. This allows for authentication of these programs so that only valid programs can be used .
Secure Boot will prevent the boot process from continuing if the software is unsigned or its signature has been modified, which could be an indication of tampering. In this way, Secure Boot keeps data safe and secure on your computer.
This security system is specifically designed to protect against UEFI bootkits and rootkits, as well as to notify users if the operating system has been modified since it was delivered by the vendor.
See also: Zoho RCE: Proof-of-Concept for dangerous bug released
Default MSI settings cause unsafe boots
According to Potocki, MSI released “7C02v3C,” a firmware update on January 18, 2022, which changed the default Secure Boot setting of its motherboards to the point where it would still boot even if security breaches were detected.
This change was to accidentally set the “Image Execution Policy” setting in the Firmware to “Always Execute” by default, allowing any image to boot the device normally.

As depicted in the image above, Secure Boot is enabled, but the 'Image Execution Policy' setting is still set to “Always Execute”, allowing your computer to boot even when there are security breaches.
Bypassing secure boot allows the use of unverified images to boot your device.
See also: Malicious PyPi 'Lolip0p' packages install info-stealing malware
Potocki explains that users should set the Execution Policy to "Deny Execute" for "Removable Media" and "Fixed Media", which should only allow signed software to launch.

After thorough analysis, the researcher discovered that MSI had never documented its changes, so he was forced to track down the introduction of this insecure default by using IFR (UEFI Internal Form Representation) to extract information about the configuration options.
Armed with this information, Potocki was able to determine which MSI motherboards were affected by the issue. A list of over 290 affected motherboards has been published on GitHub for everyone to access.
For an extra layer of security for your MSI motherboard, take a quick look at your BIOS settings to make sure the “Image Execution Policy” is set to something secure.
If you haven't upgraded your motherboard firmware since January 2022, introducing a bad default shouldn't be a reason for further postponement, as software updates contain important security fixes.
Information source: bleepingcomputer.com
