Bugs affecting several Gigabyte could allow attackers to disable UEFI and gain control of affected systems, security researchers have discovered.
See also: Over 16,000 Fortinet devices contain symlink backdoor

The issues were identified in System Management Mode (SMM), a highly privileged processor function that handles low-level functions and allows UEFI to interact directly with the computer.
SMM functions are executed in protected memory and are accessible only through System Management Interrupts (SMI), which rely on specific buffers for data processing
However, the lack of validation of these buffers could allow attackers to execute arbitrary code before the operating system has even loaded. According to the Carnegie Mellon University CERT Coordination Center (CERT/CC) , the UEFI modules in Gigabyte's firmware expose systems to such attacks.
See also: Cisco warns of backdoor in CSLU
The issues were initially identified in AMI , and the vendor had addressed the issue through private disclosures. Now, the same issues have been identified again in Gigabyte firmware, affecting dozens of products, according to reports.

Recorded as CVE-2025-7026, CVE-2025-7027, CVE-2025-7028, and CVE-2025-7029, the vulnerabilities allow attacker-defined memory write, arbitrary content writing to System Management RAM (SMRAM), and control of critical flash functions.
Successful exploitation of these vulnerabilities could allow disabling key UEFI security mechanisms, such as Secure Boot, and installing backdoors or malicious implants in the firmware, allowing an attacker to gain permanent control over the system. Such implants are not detected by traditional protection tools , as the SMM function runs at a level below the operating system.
See also: FIN7 develops Anubis Backdoor and compromises Windows systems
The specific security flaws were discovered and reported by the company Binarly, which warns that such implants could remain on the system even after reinstalling the operating system. The company also notes that these vulnerabilities can be used to bypass certain types of memory isolation implemented by hypervisors.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
