Certain motherboard models from vendors such as ASRock, ASUSTeK Computer, GIGABYTE , and MSI are affected by a security vulnerability in architectures that implement the Unified Extensible Firmware Interface (UEFI) and the Input-Output Memory Management Unit (IOMMU), which makes them vulnerable to direct memory access (DMA) attacks during the early boot phase.
See also: HybridPetya Ransomware: Is it different from Petya and NotPetya?

UEFI and IOMMU are designed to enforce a security baseline and prevent peripherals from making unauthorized accesses to memory, essentially ensuring that DMA-enabled devices cannot manipulate or inspect system memory before the operating system is loaded.
The vulnerability, discovered by Nick Peterson and Mohamed Al-Sharifi of Riot Games in certain UEFI implementations, is related to a mismatch in the DMA protection state. While the firmware indicates that DMA protection is enabled, it fails to configure and enable the IOMMU during the critical boot phase.
“This vulnerability allows a malicious PCIe device with physical access to read or modify system memory before operating system-level protections are in place,” the CERT Coordination Center (CERT/CC) in an advisory.
Successful exploitation of the vulnerability could allow a physically present attacker to trigger pre-boot code injection on affected systems running unpatched firmware and access or modify system memory via DMA transactions, long before the operating system kernel and its security features are loaded.
See also: Bitpixie vulnerability allows bypass of BitLocker encryption

The vulnerabilities that allow bypassing memory protection during early boot are listed below:
– CVE-2025-14304 (CVSS score: 7.0) – Protection mechanism failure flaw affecting ASRock, ASRock Rack and ASRock Industrial motherboards with Intel 500, 600, 700 and 800 chipsets.
– CVE-2025-11901 (CVSS score: 7.0) – Protection mechanism failure vulnerability affecting ASUS motherboards with Intel Z490, W480, B460, H410, Z590, B560, H510, Z690, B660, W680, Z790, B760 and W790 chipsets.
– CVE-2025-14302 (CVSS score: 7.0) – Protection mechanism failure vulnerability affecting GIGABYTE motherboards with Intel Z890, W880, Q870, B860, H810, Z790, B760, Z690, Q670, B660, H610, W790 chipsets and AMD X870E, X870, B850, B840, X670, B650, A620, A620A and TRX50 chipsets (The fix for TRX50 is planned for Q1 2026).
– CVE-2025-14303 (CVSS score: 7.0) – Protection mechanism failure vulnerability affecting MSI motherboards with Intel 600 and 700 chipsets.
See also: HybridPetya: Exploiting UEFI vulnerability to bypass Secure Boot

With affected vendors releasing firmware updates to fix the IOMMU initialization sequence and enforce DMA protections throughout the boot process, it is essential that end users and administrators implement them as soon as possible to protect themselves from the threat.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
