InsydeH2O UEFI software impacted by multiple vulnerabilities in SMM

Discussion in 'other security issues & news' started by ronjor, Feb 2, 2022.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    178,553
    Location:
    Texas
    Vulnerability Note VU#796611
    Original Release Date: 2022-02-01 | Last Revised: 2022-02-01

     
  2. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "The flaws are severe as they allow attackers to bypass hardware security features as well as traditional endpoint security solutions...

    Researchers at enterprise security firm Binarly have discovered no less than 23 high-impact vulnerabilities in the BIOS/UEFI firmware used by several computer vendors like Intel, AMD, Lenovo, Dell, HP, Asus, Microsoft, Fujitsu, Juniper Networks, Acer, Bull Atos, and Siemens...

    Official firmware patches are expected to roll out in the coming months, but they will most likely arrive in the second half of this year..."

    https://www.techspot.com/news/93234-new-uefi-firmware-vulnerabilities-affect-several-pc-vendors.html
     
  3. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    178,553
    Location:
    Texas
    InsydeH2O UEFI software impacted by multiple vulnerabilities in SMM
    Vulnerability Note VU#796611
    Original Release Date: 2022-02-01 | Last Revised: 2022-04-26

     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.