HomeSecurityPKfail Secure Boot bypass remains a significant risk

PKfail Secure Boot bypass remains a significant risk

About nine percent of tested firmware images use cryptographic keys that are publicly known or have been leaked in data breaches, leaving many Secure Boot vulnerable to PKfail attacks.

See also: PKfail: Allows attackers to install UEFI malware

PKfail Secure Boot

The supply chain attack is caused by the trial Secure Boot Master Key (Platform Key “PK”), which computer vendors were required to replace with their own securely.

Even though these keys were marked as “DO NOT TRUST,” they were still used by many computer manufacturers, including Acer, Dell, Fujitsu, Gigabyte, HP, Intel, Lenovo, Phoenix, and Supermicro.

The issue was discovered by Binarly in late July 2024, which warned about the use of untrusted keys, many of which have already been leaked on GitHub and other online sites, on more than eight hundred consumer and enterprise device models.

PKfail could allow threat actors to bypass Secure Boot protections and install undetectable UEFI malware on vulnerable systems, leaving users powerless to defend themselves or even discover the breach.

As part of its research, Binarly released a “PKfail scanner,” which vendors can use to upload their firmware images to see if they are using a test key.

Since its release, the scanner has found 791 vulnerable firmware submissions out of 10,095, according to the most recent count.

See also: Zero-Click vulnerability in macOS Calendar allows malicious actions

The majority of vulnerable submissions are keys from AMI (American Megatrends Inc.), followed by Insyde (61), Phoenix (4) , and one submission from Supermicro.

PKfail Secure Boot bypass remains a significant risk

For the Insyde, which were created in 2011, Binarly says that firmware image submissions reveal that they are still being used on modern devices. Previously, it was assumed that they were only found on legacy systems.

The community has also confirmed that PKfail affects specialized devices from Hardkernel, Beelink , and Minisforum, so the impact of the flaw is broader than initially estimated.

Vendor response to PKfail has generally been proactive and rapid, although not all have been quick to issue advisories about the security risk. PKfail bulletins are currently available from Dell , Fujitsu, Supermicro, Gigabyte, Intel , and Phoenix.

Several vendors have already released patches or firmware updates to remove vulnerable platform keys or replace them with production-ready cryptographic hardware, and users can obtain them by updating their BIOS.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

If your Secure Boot device is no longer supported and is unlikely to receive security updates for PKfail, it is recommended to restrict physical access to it and isolate it from more critical parts of the network.

See also: Healthcare provider LVHN pays $65 million after Ransomware attack

Malware attacks have become increasingly sophisticated, posing significant threats to both individuals and organizations. These attacks involve malicious software that is intentionally designed to cause harm, steal sensitive data, or gain unauthorized access to computer systems. Common types of malware include viruses, worms, trojans, ransomware, and spyware, each with its own methods and impacts. Protecting against malware requires a robust cybersecurity strategy, which includes up-to-date antivirus software, firewalls, and careful user practices, such as regular updates and careful email handling. As technology evolves , so do the techniques used by cybercriminals , making ongoing awareness and education vital to combating malware threats.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS