HomeSecurityPKfail: Allows attackers to install UEFI malware

PKfail: Allows attackers to install UEFI malware

Hundreds of UEFI products from 10 vendors are vulnerable to compromise due to a critical issue in the firmware supply chain, known as PKfail, which allows attackers to bypass Secure Boot and install malware.

See also: Over 3,000 GitHub accounts used to distribute malware

PKfail UEFI malware

How PKfail affects security

As the Binarly Research Team discovered , the affected devices are using a trial Secure Boot “ master key ” — also known as a Platform Key (PK) — created by American Megatrends International (AMI) . This key has been marked as “ DO NOT TRUST ” and upstream vendors should replace it with their own securely generated keys .

“This Platform Key, which manages Secure Boot databases and maintains the chain of trust from firmware to operating system, is often not replaced by OEMs or device vendors, resulting in devices shipping with untrusted keys,” said the Binarly Research Team.

UEFI device manufacturers that used untrusted keys and exposed 813 products include Acer, Aopen, Dell, Formelife, Fujitsu, Gigabyte, HP, Intel, Lenovo, and Supermicro.

In May 2023, Binarly discovered a supply chain security incident involving leaked private keys from Intel Boot Guard, affecting multiple suppliers. As originally reported by BleepingComputer, the Money Message leaked MSI's source code for the firmware used by the company's motherboards.

The code contained private image signing keys for 57 MSI products and private Intel Boot Guard keys for another 116 MSI products.

See also: LummaC2 malware uses Steam as a C2 server

Earlier this year, a private key from American Megatrends International (AMI) related to the Secure Boot “master key” was also leaked, affecting several enterprise device manufacturers. The affected devices are still in use, and the key is being used on recently released enterprise devices.

PKfail: Allows attackers to install UEFI malware

As Binarly explains, successful exploitation of this issue allows malicious actors with access to vulnerable devices and the private portion of the platform key to bypass Secure Boot by manipulating the Key Exchange Key (KEK), Signature Database (db) , and Forbidden Signature Database (dbx).

After compromising the entire security chain via PKfail, from firmware to operating system, they can sign malicious code, which allows them to deploy UEFI malware like CosmicStrand and BlackLotus.

To mitigate PKfail, it is recommended that vendors generate and manage the Platform Key following cryptographic key management best practices, such as hardware security modules. It is also important to replace any test keys provided by third-party BIOS vendors such as AMI with their own securely generated keys. Users should monitor firmware updates issued by device vendors and apply any security patches that address PKfail supply chain issues as soon as possible.

Binarly also published the website pk.fail, which helps users scan free firmware binaries to find devices vulnerable to PKfail and malicious payloads.

See also: Daggerfly group targets Taiwan with MgBot malware

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Malware is designed to damage, exploit, or otherwise compromise computer systems and networks. Common types of malware include viruses, worms, Trojans, ransomware , and spyware. These threats can lead to data breaches, system failures, and significant financial losses. Effective cybersecurity measures, including antivirus software and regular system updates, are essential to protect against malware. Users should also be cautious when browsing the Internet and avoid downloading attachments or clicking on links from untrusted sources.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS