Dell SecureAssist contained RCE flaw allowing miscreants to remotely reflash your BIOS with code of their creation
- Reference: 1624643110
- News link: https://www.theregister.co.uk/2021/06/25/dell_secureassist_biosconnect_vulns_rce/
- Source link:
A remote BIOS reflasher built into a pre-installed Dell support tool, SupportAssist, would accept "any valid wildcard certificate" from a pre-defined list of certificate authorities, giving attackers a vital foothold deep inside targeted machines – though Dell insists the exploit is only viable if a logged-in user runs the SupportAssist utility and in combination with a man-in-the-middle attack.
Consisting of four daisy-chained flaws, the vulns have a combined CVSSv3.1 score of 8.1 and allow remote code execution at an early stage of booting a vulnerable system by authenticated attackers. Updates for SupportAssist are available from Dell to mitigate the vulns, which infosec firm Eclypsium reckons affect about 30 million laptops and PCs.
[1]
The company, which [2]blogged about the vulns, said: "Such code may alter the initial state of an operating system, violating common assumptions on the hardware/firmware layers and breaking OS-level security controls."
[3]You won't want that Linux bling if it comes from Pling: Marketplace platform has critical vulnerabilities
[4]Google pushes bug databases to get on the same page for open-source security
[5]Fashion titan French Connection says 'FCUK' as REvil-linked ransomware makes off with data
[6]Zephyr OS Bluetooth vulnerabilities left smart devices open to attack
The wildcard cert vuln (CVE-2021-21571) came about because a SupportAssist feature called BIOSConnect did not properly validate the TLS certificate for https://downloads.dell.com after carrying out a DNS lookup for that domain via Google's 8.8.8.8 DNS server. BIOSConnect would accept any wildcard certificate from a list of certificate authorities as valid instead of the actual certificate for the Dell downloads site, said Eclypsium.
"When UEFI Secure Boot is disabled, this vulnerability can be used to gain arbitrary remote code execution in the UEFI/pre-boot environment on the client device," the firm continued.
[7]
[8]
Further details of the three other vulns, coyly referred to only as "a buffer overflow" by Dell and Eclypsium, will be revealed at Def Con. Tracked as CVE-2021-21572 through -21574 inclusive, these were cumulatively rated as 7.2 on the CVSSv3.1 scale. CVE-2021-21573 and CVE-2021-21574 have both "been remediated on the server side" according to Dell and "require no additional customer action."
Dell was less than chuffed judging by the wording of its advisory about the flaws, though it confirmed it had worked with Eclypsium from March, well prior to public disclosure.
[9]
"To exploit the vulnerability chain in BIOSConnect, a malicious actor must separately perform additional steps before a successful exploit, including: compromise a user's network, obtain a certificate that is trusted by one of the Dell UEFI BIOS https stack's built-in Certificate Authorities, and wait for a user who is physically present at the system to use the BIOSConnect feature," [10]sniffed an unimpressed Dell .
Eclypsium agreed, saying: "An attack scenario would require an attacker to be able to redirect the victim’s traffic, such as via a Machine-in-the-Middle (MITM) attack."
Bharat Jogi, Qualys senior manager of vulnerability and threat research, commented: "The four vulnerabilities on Dell devices are highly concerning. BIOS is critical for a device boot process and its security is vital to ensure safety of the entire device. This is especially important in the current environment due to the increased wave of supply chain attacks. This chain of security vulnerabilities allow for bypass of Secure Boot protections, can be exploited to take complete control of the device and hence organisations should prioritise patching."
[11]
If you don't fancy upgrading SecureAssist, an effective mitigation is simply to delete the utility, according to Dell. ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YNZR-zFtSIkXn9gyKzmXJQAAAAs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://eclypsium.com/2021/06/24/biosdisconnect/
[3] https://www.theregister.com/2021/06/24/pling_linux_flaws/
[4] https://www.theregister.com/2021/06/24/google_security_fix/
[5] https://www.theregister.com/2021/06/24/french_connection_says_fcuk_as/
[6] https://www.theregister.com/2021/06/22/zephyr_os_bluetooth_vulnerabilities/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNZR-zFtSIkXn9gyKzmXJQAAAAs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNZR-zFtSIkXn9gyKzmXJQAAAAs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNZR-zFtSIkXn9gyKzmXJQAAAAs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.dell.com/support/kbdoc/en-uk/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNZR-zFtSIkXn9gyKzmXJQAAAAs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Re: Just Wow! Say it ain't so!
...renders the hardware crap if you reinstall windows,...
Well then, don't (re)install windows and put something more sane on it. Then all will be fine. You say as much in "Friends don't let friends drive windows while breathing..." . Therefore, no need to complain any further, just install The Right (TM) operating system and be happy ever after.
Re: Just Wow! Say it ain't so!
Some places don't have a Penguinista at the ready, OK most places... so you get my point.
Well I'm glad I reinstalled my mom's PC last year
Since it was still running Windows 7 I finally had to drag her into Windows 7, but the one side benefit was that I upgraded her to an SSD which meant reinstalling from scratch. Thus no Dell crapware on her pristine Windows 10 install.
Though sounds like just as I had to tweak her Windows 7 to avoid having it upgrade to Windows 10 on its own, I will soon have to do the same to stop it from upgrading to Windows 11. Sigh.
Optional
Hmm. My Dell 2000 from 2013 seems to be too old to be vulnerable. F2 brings up something quite different from what the info on the Dell site says. Oh well, due to paranoia, I never have networking on while it is booting. At least, the cable isn't plugged in, and I very rarely use it with Wifi (it's a foot from the router), so that's turned off at the Ubuntu Mate level. It still has Windows 8.1 on it, which I haven't deliberately booted for a couple of years, and which I never let onto the internet. Paranoid? Me? Dang Windows rewrites the boot order stuff on every boot, whereas Linux only does it on an install, so I have to be quick with the F-key that changes boot order...
This is why it’s best to boot off a Windows thumb drive, delete all partitions and install Windows fresh the first time you turn it on. Oh, and don’t connect the network cable or WiFi until you’re at the desktop. Lenovo, HP, Dell, they’re all getting worse with the crapware again like they were in the late 90’s and Naughts.
Just Wow! Say it ain't so!
simply to delete the utility, according to Dell. ®
My experience with deleting vendor specific utilities renders the hardware crap if you reinstall windows, it will reinstall, incorrectly and be toilet paper on your shoe, how many times must you bang your head against the wall before you learn? Friends don't let friends drive windows while breathing...