HomeSecurityUEFI Vulnerability Allows DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards

UEFI vulnerability allows DMA attacks on ASRock, ASUS, GIGABYTE, MSI motherboards

Certain motherboard models from vendors such as ASRock, ASUSTeK Computer, GIGABYTE , and MSI are affected by a security vulnerability in architectures that implement the Unified Extensible Firmware Interface (UEFI) and the Input-Output Memory Management Unit (IOMMU), which makes them vulnerable to direct memory access (DMA) attacks during the early boot phase.

See also: HybridPetya Ransomware: Is it different from Petya and NotPetya?

UEFI

UEFI and IOMMU are designed to enforce a security baseline and prevent peripherals from making unauthorized accesses to memory, essentially ensuring that DMA-enabled devices cannot manipulate or inspect system memory before the operating system is loaded.

The vulnerability, discovered by Nick Peterson and Mohamed Al-Sharifi of Riot Games in certain UEFI implementations, is related to a mismatch in the DMA protection state. While the firmware indicates that DMA protection is enabled, it fails to configure and enable the IOMMU during the critical boot phase.

“This vulnerability allows a malicious PCIe device with physical access to read or modify system memory before operating system-level protections are in place,” the CERT Coordination Center (CERT/CC) in an advisory.

Successful exploitation of the vulnerability could allow a physically present attacker to trigger pre-boot code injection on affected systems running unpatched firmware and access or modify system memory via DMA transactions, long before the operating system kernel and its security features are loaded.

See also: Bitpixie vulnerability allows bypass of BitLocker encryption

UEFI vulnerability allows DMA attacks on ASRock, ASUS, GIGABYTE, MSI motherboards

The vulnerabilities that allow bypassing memory protection during early boot are listed below:

– CVE-2025-14304 (CVSS score: 7.0) – Protection mechanism failure flaw affecting ASRock, ASRock Rack and ASRock Industrial motherboards with Intel 500, 600, 700 and 800 chipsets.

– CVE-2025-11901 (CVSS score: 7.0) – Protection mechanism failure vulnerability affecting ASUS motherboards with Intel Z490, W480, B460, H410, Z590, B560, H510, Z690, B660, W680, Z790, B760 and W790 chipsets.

– CVE-2025-14302 (CVSS score: 7.0) – Protection mechanism failure vulnerability affecting GIGABYTE motherboards with Intel Z890, W880, Q870, B860, H810, Z790, B760, Z690, Q670, B660, H610, W790 chipsets and AMD X870E, X870, B850, B840, X670, B650, A620, A620A and TRX50 chipsets (The fix for TRX50 is planned for Q1 2026).

– CVE-2025-14303 (CVSS score: 7.0) – Protection mechanism failure vulnerability affecting MSI motherboards with Intel 600 and 700 chipsets.

See also: HybridPetya: Exploiting UEFI vulnerability to bypass Secure Boot

UEFI vulnerability allows DMA attacks on ASRock, ASUS, GIGABYTE, MSI motherboards

With affected vendors releasing firmware updates to fix the IOMMU initialization sequence and enforce DMA protections throughout the boot process, it is essential that end users and administrators implement them as soon as possible to protect themselves from the threat.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS