Vulnerability in Acer Laptops Allows Attackers to Disable Secure Boot By Orbit Brain November 29, 2022 0 179 viewsCyber Security News House › Endpoint SafetyVulnerability in Acer Laptops Permits Attackers to Disable Safe BootBy Ionut Arghire on November 29, 2022TweetA vulnerability impacting a number of Acer laptop computer fashions might enable an attacker to disable the Safe Boot characteristic and bypass safety protections to put in malware.Tracked as CVE-2022-4020 (CVSS rating of 8.1), the vulnerability was recognized within the HQSwSmiDxe DXE driver, which checks for the existence of the ‘BootOrderSecureBootDisable’ NVRAM variable to disable Safe Boot.“Vulnerability within the HQSwSmiDxe DXE driver on some shopper Acer Pocket book gadgets might enable an attacker with elevated privileges to change UEFI Safe Boot settings by modifying an NVRAM variable,” a Nationwide Vulnerability Database advisory explains.Acer explains that the vulnerability might enable an attacker to tamper with Safe Boot settings just by creating NVRAM variables. As a result of the affected firmware driver solely checks for the existence of the variables, their precise worth just isn’t essential.“By disabling the Safe Boot characteristic, an attacker can load their very own unsigned malicious bootloader to permit absolute management over the OS loading course of. This may enable them to disable or bypass protections to silently deploy their very own payloads with the system privileges,” Acer notes.Impacted system fashions, the pc maker says, embody Aspire A315-22, A115-21, and A315-22G, and Extensa EX215-21 and EX215-21G.“Acer is engaged on a BIOS replace to resolve this concern that can be posted on the Acer Help website. Acer recommends updating your BIOS to the most recent model to resolve this concern. This replace can be included as a essential Home windows replace,” the corporate notes.ESET safety researcher Martin Smolar was credited for locating and reporting the vulnerability.In response to ESET, this concern is like CVE-2022-3431, a vulnerability within the DXE driver BootOrderDxe of some Lenovo laptops which, simply because the HQSwSmiDxe DXE driver, checks for the existences of a BootOrderSecureBootDisable variable and disables Safe Boot if it exists.ESET warned of this Lenovo bug in early November, urging customers to replace the BIOS on impacted gadgets as quickly as doable.Now, the cybersecurity firm is elevating the alarm on this Acer vulnerability, urging customers to maintain an eye fixed out for the patches.“Along with Lenovo vulnerabilities we disclosed earlier this month, we found one other related vulnerability in Acer laptops. Similar as in Lenovo case, it permits deactivating UEFI Safe Boot by creating NVRAM variable instantly from OS,” ESET notes.Associated: Lenovo Patches UEFI Code Execution Vulnerability Affecting Many LaptopsAssociated: HP Patches UEFI Vulnerabilities Affecting Over 200 Computer systemsAssociated: Excessive-Severity UEFI Vulnerabilities Patched in Dell Enterprise LaptopsGet the Day by day Briefing Most CurrentMost LearnRansomware Gang Takes Credit score for Maple Leaf Meals HackVulnerability in Acer Laptops Permits Attackers to Disable Safe BootCybercriminals Promoting Entry to Networks Compromised by way of Current Fortinet VulnerabilityOracle Fusion Middleware Vulnerability Exploited within the WildCensus Bureau Chief Defends New Privateness Device In opposition to CriticsVirginia County Confirms Private Info Stolen in Ransomware AssaultMission Zero Flags ‘Patch Hole’ Issues on AndroidIrish Regulator Fines Meta 265 Million Euros Over Information BreachHack-for-Rent Group Targets Android Customers With Malicious VPN AppsCrackdown on African Cybercrime Results in Arrests, Infrastructure TakedownSearching for Malware in All of the Unsuitable Locations?First Step For The Web’s subsequent 25 years: Including Safety to the DNSTattle Story: What Your Laptop Says About YouBe in a Place to Act By way of Cyber Situational ConsciousnessReport Exhibits Closely Regulated Industries Letting Social Networking Apps Run Rampant2010, A Nice Yr To Be a Scammer.Do not Let DNS be Your Single Level of FailureLearn how to Establish Malware in a BlinkDefining and Debating Cyber WarfareThe 5 A’s that Make Cybercrime so EnticingLearn how to Defend In opposition to DDoS AssaultsSafety Budgets Not in Line with ThreatsAnycast – Three Causes Why Your DNS Community Ought to Use ItThe Evolution of the Prolonged Enterprise: Safety Methods for Ahead Considering OrganizationsUtilizing DNS Throughout the Prolonged Enterprise: It’s Dangerous Enterprise Acer bios CVE-2022-4020 disable Secure Boot UEFI vulnerability Orbit Brainhttp://orbitbrain.com/ Orbit Brain is the senior science writer and technology expert. Our aim provides the best information about technology and web development designing SEO graphics designing video animation tutorials and how to use software easy waysand much more. Like Best Service Latest Technology, Information Technology, Personal Tech Blogs, Technology Blog Topics, Technology Blogs For Students, Futurism Blog.
iOS 12 Update for Older iPhones Patches Exploited VulnerabilityIntroducing the Cyber Security News iOS 12 Update for Older iPhones Patches Exploited Vulnerability.... September 1, 2022 Cyber Security News
CISA, FBI Warn Organizations of Zeppelin Ransomware AttacksIntroducing the Cyber Security News CISA, FBI Warn Organizations of Zeppelin Ransomware Attacks.... August 13, 2022 Cyber Security News
Online Event Today: Security Operations SummitIntroducing the Cyber Security News Online Event Today: Security Operations Summit.... December 6, 2022 Cyber Security News
Remote Code Execution Vulnerabilities Found in TP-Link, NetComm RoutersIntroducing the Cyber Security News Remote Code Execution Vulnerabilities Found in TP-Link, NetComm Routers.... January 19, 2023 Cyber Security News
ICS Patch Tuesday: Siemens, Schneider Electric Fix Only 11 VulnerabilitiesIntroducing the Cyber Security News ICS Patch Tuesday: Siemens, Schneider Electric Fix Only 11 Vulnerabilities.... August 9, 2022 Cyber Security News
2022 CISO Forum: All Sessions on DemandIntroducing the Cyber Security News 2022 CISO Forum: All Sessions on Demand.... September 16, 2022 Cyber Security News