Discover unbeatable deals on top-rated products — shop smart and save big every day at TopBargainGo!

New UEFI Firmware Flaw Exposes Common Motherboards To Assaults

Cybersecurity consultants simply discovered a flaw in the UEFI firmware that many trendy motherboards use. The “bug” may let attackers do direct reminiscence entry (DMA) assaults on programs, which can allow unauthorized customers to achieve deep and protracted entry to affected programs underneath sure circumstances, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.

To provide you context, the PC motherboard comprises low-level software program known as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} elements. One in all its main safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s meant to safeguard system reminiscence. If arrange appropriately, the IOMMU stops exterior units from studying or writing to random elements of system RAM.

Parts akin to PCIe growth playing cards, Thunderbolt peripherals, GPUs, and comparable {hardware} that may entry reminiscence immediately with out passing by way of the CPU are included in DMA-capable units. Malicious or compromised {hardware} can have much less of an affect as a result of these units are restricted to specific reminiscence areas if the IOMMU is operational and correctly initialized.

The just lately found vulnerability is attributable to the flawed manner this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, although the IOMMU was by no means totally or appropriately arrange, after which the working system consequently assumes that reminiscence protections are carried out, although they aren’t actively enforced.

The problem is being tracked underneath a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options in a different way.

Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, had been the primary ones to determine the vulnerability. Vanguard, Riot’s anti-cheat system, is carried out on the kernel degree and incorporates safeguards which are meant to stop unauthorized system manipulation. Valorant could also be prevented from launching on programs which are affected by this particular flaw, as it detects an unsafe {hardware} safety state.

There may be an essential limitation to consider, although the attainable impact might be horrible: the flexibility to bodily entry the system and join a malicious PCIe or comparable system earlier than the working system boots up are stipulations for a DMA assault. Consequently, the likelihood of widespread exploitation is considerably diminished, notably for residential customers.

Customers are being suggested to monitor updates from their motherboard producers and apply any out there firmware patches. Updating the UEFI firmware continues to be important to preserving system safety, notably in mild of the continued evolution of hardware-level assaults.

Filed in Computers. Learn extra about , , , and .

Trending Merchandise

0
Add to compare
- 12% Lenovo 15.6″ FHD Laptop, Inte...
Original price was: $429.00.Current price is: $378.99.

Lenovo 15.6″ FHD Laptop, Inte...

0
Add to compare
- 19% Lenovo V14 Gen 3 Enterprise Laptop ...
Original price was: $739.00.Current price is: $599.00.

Lenovo V14 Gen 3 Enterprise Laptop ...

0
Add to compare
- 20% LG UltraGear QHD 27-Inch Gaming Mon...
Original price was: $299.99.Current price is: $240.20.

LG UltraGear QHD 27-Inch Gaming Mon...

0
Add to compare
- 23% ASUS 31.5” 4K HDR Eye Care Mon...
Original price was: $299.00.Current price is: $229.00.

ASUS 31.5” 4K HDR Eye Care Mon...

0
Add to compare
- 40% Wireless Keyboard and Mouse Combo, ...
Original price was: $25.99.Current price is: $15.72.

Wireless Keyboard and Mouse Combo, ...

0
Add to compare
- 13% Wireless Keyboard and Mouse Combo, ...
Original price was: $39.99.Current price is: $34.99.

Wireless Keyboard and Mouse Combo, ...

0
Add to compare
- 10% LG FHD 32-Inch Computer Monitor 32M...
Original price was: $199.99.Current price is: $179.99.

LG FHD 32-Inch Computer Monitor 32M...

0
Add to compare
- 10% Logitech MK540 Superior Wi-fi Keybo...
Original price was: $49.99.Current price is: $44.99.

Logitech MK540 Superior Wi-fi Keybo...

0
Add to compare
- 27% TP-Link Smart WiFi 6 Router (Archer...
Original price was: $79.99.Current price is: $58.19.

TP-Link Smart WiFi 6 Router (Archer...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

TopBargainGo
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart