Lenovo ThinkPwn UEFI exploit also affects products from other vendors

A critical vulnerability that was once just lately found within the low-level firmware of Lenovo ThinkPad systems additionally reportedly exists in merchandise from different providers, together with HP and Gigabyte Technology.

An make the most for the vulnerability was revealed last week and can be utilized to execute rogue code within the CPU's privileged SMM (Device Administration Mode).

This stage of access can then be used to install a stealthy rootkit throughout the computer's Unified Extensible Firmware Interface (UEFI) — the modern BIOS — or to disable Windows safety features equivalent to Stable Boot, Digital Secure Mode and Credential Shield that rely upon the firmware being locked down.

The take advantage of, dubbed ThinkPwn, used to be launched by means of a safety researcher named Dmytro Oleksiuk last week with out sharing it with Lenovo in advance. LOOKAHEAD COMPLETE. Lenovo mentioned in a safety advisory that the vulnerable code originated in a UEFI package provided to the company by way of considered one of its unbiased BIOS carriers (IBVs). These are companies that take the UEFI reference implementation and extend it, then sell the resulting bundle to LAPTOP producers.

The Fact That the vulnerability used to be within the UEFI implementation of an IBV made it possible that other carriers except Lenovo used the susceptible firmware of their merchandise.

This was once demonstrated over the weekend by using a researcher named Alex James, who mentioned on Twitter that he found the vulnerable code throughout the firmware of an HP Pavilion dv7-4087cl laptop. The firmware used to be supplied by way of Insyde Tool, a Taiwanese IBV.

James later suggested that the inclined code exists within the firmware of a number of motherboards made by Taiwanese computer hardware producer Gigabyte Technology. The prone models embody Gigabyte's Z77X-UD5H, Z68-UD3H, Z87MX-D3H and Z97-D3H.

Intel, HP and Gigabyte did not instantly respond to a request for remark.

Oleksiuk believes that the vulnerability originated in Intel's reference code for its Eight-collection chipsets and that it was once fastened in mid-2014. Alternatively, because then Oleksiuk has found The Identical inclined code inside older open Supply firmware for some Intel motherboards.</p> <p>Lenovo mentioned in a <a href="" target="new">safety advisory that the vulnerable code originated in a UEFI package provided to the company by way of considered one of its unbiased BIOS carriers (IBVs). These are companies that take the UEFI reference implementation and extend it, then sell the resulting bundle to LAPTOP producers.</p> <p>The Fact That the vulnerability used to be within the UEFI implementation of an IBV made it possible that other carriers except Lenovo used the susceptible firmware of their merchandise.</p> <p>This was once demonstrated over the weekend by using a researcher named Alex James, who mentioned on Twitter that he found the vulnerable code throughout the firmware of an HP Pavilion dv7-4087cl laptop. The firmware used to be supplied by way of Insyde Tool, a Taiwanese IBV.</p> <p>James later suggested that the inclined code exists within the firmware of a number of motherboards made by Taiwanese computer hardware producer Gigabyte Technology. The prone models embody Gigabyte’s Z77X-UD5H, Z68-UD3H, Z87MX-D3H and Z97-D3H.</p> <aside class="nativo-promo tablet desktop" id="" /> <p>Intel, HP and Gigabyte did not instantly respond to a request for remark.</p> <p>Oleksiuk believes that the vulnerability originated in Intel’s reference code for its Eight-collection chipsets and that it was once fastened in mid-2014. Then Again, on the grounds that there have been no public advisories about it, it can be possible that IBVs and PC manufacturers overlooked the patch and persevered to use an older model of the reference code as base for his or her UEFI.</p> <p>Unfortunately, the affected merchandise from Lenovo, HP and Gigabyte are most certainly Simply the tip of the iceberg and it’ll take a long time for all providers to Take A Look At their firmware and unencumber patches. 