News: 1701461526

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UEFI flaws allow bootkits to pwn potentially hundreds of devices using images

(2023/12/01)


Hundreds of consumer and enterprise devices are potentially vulnerable to bootkit exploits through unsecured BIOS image parsers.

Security researchers have identified vulnerabilities in UEFI system firmware from major vendors which they say could allow attackers to hijack poorly maintained image libraries to quietly deliver malicious payloads that bypass Secure Boot, Intel Boot Guard, AMD Hardware-Validated Boot, and others.

Dubbed "LogoFail," we're told the set of vulnerabilities allows attackers to use malicious image files that are loaded by the firmware during the boot phase as a means of quietly delivering payloads such as bootkits.

[1]

The vulnerabilities affect the image parsing libraries used by various firmware vendors, most of which are exposed to the flaws, according to the researchers at Binarly.

[2]

[3]

Image parsers are firmware components responsible for loading logos of vendors, or workplaces in cases where work-issued machines are configured to do so, flashing them on the display as the machine boots.

Attackers could feasibly inject their own image file into the EFI system partition, which is then parsed during boot and is capable of quietly installing a malicious payload, such as a bootkit, with persistence.

[4]

Binarly said the discovery, which started life as a small side project but turned into a much larger, industry-wide disclosure, should be considered more dangerous than the [5]BlackLotus bootkit from earlier this year.

"LogoFAIL differs from BlackLotus or [6]BootHole threats because it doesn't break runtime integrity by modifying the bootloader or firmware component," said the researchers in a [7]blog post .

[8]Uh-oh, update Google Chrome – exploit already out there for one of these 6 security holes

[9]Weak session keys let snoops take a byte out of your Bluetooth traffic

[10]Trio of major holes in ownCloud expose admin passwords, allow unauthenticated file mods

[11]OpenCart owner turns air blue after researcher discloses serious vuln

"In this case, we are dealing with continued exploitation with a modified boot logo image, triggering the payload delivery in runtime, where all the integrity and security measurements happen before the firmware components are loaded."

All three of the major independent BIOS vendors – AMI, Insyde, and Phoenix – are affected by the issues, as well as devices from Intel, Acer, and Lenovo .

"Hundreds of consumer and enterprise-grade devices from various vendors, including Intel, Acer, and Lenovo, are potentially vulnerable," the researchers added.

[12]

"The exact list of affected devices is still being determined but it's crucial to note that all three major IBVs are impacted – AMI, Insyde, and Phoenix due to multiple security issues related to image parsers they are shipping as a part of their firmware."

Almost any device powered by the named vendors is thought to be affected "in one way or another," and the vulnerability spans both x86 and ARM architectures.

The researchers will unveil the issues in greater detail next week, debuting the full research on stage at Black Hat Europe in London on December 6.

The talk will include full details of how the vulnerabilities can be exploited in what they say can be simplified into a three-step process.

Binarly claimed that the industry hasn't seen any public documentation of attacks related to image parsers since a [13]presentation from 2009 [PDF] at Black Hat USA, work that saw Rafal Wojtczuk and Alexander Tereshkin exploiting a BMP parser bug.

Since then, the number of image parsers has increased, ones that cover more file types and subsequently increase the potential attack surface, they said. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZWpllkqbFW7CAMqLeDMoCAAAAIA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZWpllkqbFW7CAMqLeDMoCAAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZWpllkqbFW7CAMqLeDMoCAAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZWpllkqbFW7CAMqLeDMoCAAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/03/01/blacklotus_malware_eset/

[6] https://www.theregister.com/2020/07/29/grub2_code_exec_flaw/

[7] https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html

[8] https://www.theregister.com/2023/11/30/chrome_zeroday/

[9] https://www.theregister.com/2023/11/30/bluetooth_bluffs_attacks_are_no/

[10] https://www.theregister.com/2023/11/27/three_major_vulnerabilities_in_owncloud/

[11] https://www.theregister.com/2023/11/24/opencart_vulnerability_dispute/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZWpllkqbFW7CAMqLeDMoCAAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.blackhat.com/presentations/bh-usa-09/WOJTCZUK/BHUSA09-Wojtczuk-AtkIntelBios-SLIDES.pdf

[14] https://whitepapers.theregister.com/



Blimey....

Joe W

"Exploits bypass most secure boot solutions from the biggest chip vendors"

Yeah.

Great.

Bloody brilliant. So.... why do we insist on the bloody mess? F' that.

abend0c4

If a picture taints a thousand and twenty-four words...

Paul Crawford

Who would have guessed that the stupid complexity of your typical UEFI start-up code, along with little on no peer review, would have lead to security holes?

Is this only UEFI?

Will Godfrey

In the motherboard boot menu none of my machines are configured to start with this, so would I be safe - at least from this specific attack?

Re: Is this only UEFI?

David 132

Yes, my understanding is that machines starting in legacy BIOS mode - bootsector, etc - aren't affected by this vulnerability.

LogoFAIL, if my reading of this article's correct, relies on a malformed image placed in the root EFI partition on the boot drive. This images is loaded & parsed by the EFI firmware during boot, before the firmware hands over control of the boot process to the OS on its partition.

So if you're not using UEFI boot, and don't have an EFI partition (NB - these are normally hidden), you should be OK.

Remember, an int is not always 16 bits. I'm not sure, but if the 80386 is one
step closer to Intel's slugfest with the CPU curve that is asymptotically
approaching a real machine, perhaps an int has been implemented as 32 bits by
some Unix vendors...?
-- Derek Terveer