Microsoft has announced a new Defender for IoT feature that will allow the firmware of embedded Linux devices, such as routers, to be analyzed for security vulnerabilities and common weaknesses.

See also: Microsoft: Temporary fix for slow Outlook Desktop saving
Called Firmware Analysis and now available in public preview, the new feature can detect a wide range of vulnerabilities, from hard-coded user accounts and outdated or vulnerable open source packages to the use of a manufacturer's private cryptographic signing key.
“Firmware analysis takes a binary firmware image running on an IoT and performs an automated analysis to identify potential vulnerabilities and security weaknesses,” says Microsoft’s Derick Naef.
“This analysis provides information about the software inventory, vulnerabilities, and certificates of IoT devices, without requiring the deployment of an endpoint agent.”
The following features are currently available for analyzing the firmware security of IoT devices:
- Software Bill of Materials (SBOM): Provides a list of the open source packages used to build the firmware, indicating the package version and corresponding license agreements.
- CVE Analysis: Offers information about firmware components with publicly known security vulnerabilities and exposures.
- Binary hardening analysis: Detects binaries that have been compiled without security flags, such as buffer overflow protection, position-independent executables, and other common hardening techniques.
- SSL Certificate Analysis : Reveals expired and revoked TLS/SSL certificates within the firmware.
- Public and private key analysis: Verifies the necessity and authenticity of public and private cryptographic keys located in the firmware.
- Password hash export: Ensures that user account password hashes use secure cryptographic algorithms.

Suggestion: Message Queuing: Critical flaws in Microsoft service
To use it, users need to go to the “Firmware Analysis (Preview)” feature in Defender for IoT and upload the Linux-based firmware image from their device.
The system will then decompress the image to scan the embedded file system and analyze the loaded firmware for hidden hackers.
It is important to note that only compiled and unencrypted Linux-based firmware images obtained from your device vendor can be analyzed with Defender for IoT Firmware Analysis. Also, the image size must not exceed 1 GB.
"The Defender for IoT Firmware Analysis feature is automatically available if you access Defender for IoT using the Security Admin, Contributor, or Owner role," Microsoft says.
“If you only have the SecurityReader role or want to use Firmware Analysis as a standalone feature, then your Administrator must grant the FirmwareAnalysisAdmin role.”.
Read also: Microsoft Sharepoint out due to incorrect TLS certificate
source of information:bleepingcomputer.com
