Qualcomm UEFI Flaws Expose Microsoft, Lenovo, Samsung Devices to Attacks By Orbit Brain January 6, 2023 0 349 viewsCyber Security News Residence › Endpoint SafetyQualcomm UEFI Flaws Expose Microsoft, Lenovo, Samsung Units to AssaultsBy Eduard Kovacs on January 06, 2023TweetMany gadgets made by Microsoft, Lenovo, Samsung and sure others are affected by probably critical UEFI firmware vulnerabilities in Qualcomm Snapdragon chips.Qualcomm introduced this week the supply of patches for a dozen vulnerabilities, together with 5 connectivity- and boot-related points found by researchers at firmware safety firm Binarly.Alex Matrosov, founder and CEO of Binarly, instructed SecurityWeek that they found a complete of 9 vulnerabilities whereas analyzing the firmware for Lenovo Thinkpad X13s laptops powered by the Qualcomm Snapdragon system-on-a-chip (SoC).Additional evaluation revealed that whereas a number of the 9 flaws are particular to Lenovo gadgets, 5 of them impression Qualcomm reference code, which suggests the vulnerabilities are additionally current in laptops and different gadgets utilizing Snapdragon chips.The Snapdragon CPU makes use of the Arm structure and Matrosov stated that is the primary such disclosure of UEFI firmware vulnerabilities associated to the Arm machine ecosystem.In keeping with Binarly, the Qualcomm vulnerabilities have been confirmed to impression — along with Lenovo gadgets — Arm-based Microsoft Floor and the Home windows Dev Package 2023 (Undertaking Volterra) computer systems, in addition to Samsung merchandise.“Primarily based on Qualcomm’s advisory, the variety of affected chipsets is very large,” Matrosov stated through e mail.Two forms of vulnerabilities have been found — stack-based buffer overflows and out-of-bounds learn points — each associated to the DXE driver. They are often exploited by native attackers with elevated privileges, in response to Lenovo’s advisory.Matrosov defined that three of the vulnerabilities can result in arbitrary code execution they usually have been assigned a ‘excessive severity’ score. These flaws could be exploited for a Safe Boot bypass, they usually “allow an attacker to realize persistence on a tool by gaining ample privileges to put in writing to the file system, thus permitting an attacker to cross an additional safety boundary to simplify assaults on TrustZone.”The remaining safety holes have been rated ‘medium severity’ they usually can result in info disclosure.Qualcomm stated patches for the vulnerabilities discovered by Binarly have been made out there to prospects in November 2022, and the corporate has inspired affected finish customers to use safety updates after they change into out there from machine makers.Binarly plans on disclosing technical particulars in a weblog submit scheduled for January 9.Associated: New Firmware Vulnerabilities Affecting Hundreds of thousands of Units Enable Persistent EntryAssociated: 16 Vulnerabilities Present in Firmware of HP Enterprise UnitsAssociated: Lenovo Patches UEFI Code Execution Vulnerability Affecting Many LaptopsGet the Every day Briefing Most CurrentMost LearnSASE Firm Netskope Raises $401 MillionRussian Turla Cyberspies Leveraged Different Hackers’ USB-Delivered MalwarePerson Paperwork Overwritten With Malicious Code in Current Dridex Assaults on macOSRansomware Hit 200 US Gov, Training and Healthcare Organizations in 2022Qualcomm UEFI Flaws Expose Microsoft, Lenovo, Samsung Units to AssaultsRackspace Completes Investigation Into Ransomware AssaultFrance Regulator Raps Apple Over App Retailer AdvertisementsExtra Political Storms for TikTok After US Authorities BanPredictions 2023: Large Tech’s Coming Safety Purchasing SpreeZoho Urges ManageEngine Customers to Patch Critical SQL Injection VulnerabilityOn the lookout for Malware in All of the Flawed Locations?First Step For The Web’s subsequent 25 years: Including Safety to the DNSTattle Story: What Your Pc Says About YouBe in a Place to Act By way of Cyber Situational ConsciousnessReport Reveals Closely Regulated Industries Letting Social Networking Apps Run Rampant2010, A Nice Yr To Be a Scammer.Do not Let DNS be Your Single Level of FailureLearn how to Establish Malware in a BlinkDefining and Debating Cyber WarfareThe 5 A’s that Make Cybercrime so EnticingLearn how to Defend In opposition to DDoS AssaultsSafety Budgets Not in Line with ThreatsAnycast – Three Causes Why Your DNS Community Ought to Use ItThe Evolution of the Prolonged Enterprise: Safety Methods for Ahead Considering OrganizationsUtilizing DNS Throughout the Prolonged Enterprise: It’s Dangerous EnterpriseSecurityWeek Podcast ARM chips firmware lenovo Microsoft Samsung UEFI vulnerability Orbit Brainhttp://orbitbrain.com/ Orbit Brain is the senior science writer and technology expert. Our aim provides the best information about technology and web development designing SEO graphics designing video animation tutorials and how to use software easy waysand much more. Like Best Service Latest Technology, Information Technology, Personal Tech Blogs, Technology Blog Topics, Technology Blogs For Students, Futurism Blog.
Networking Tech Vulnerability Could Be Used to Hack Spacecraft: ResearchersIntroducing the Cyber Security News Networking Tech Vulnerability Could Be Used to Hack Spacecraft: Researchers.... November 16, 2022 Cyber Security News
Industry Reactions to Govt Requiring Security Guarantees From Software VendorsIntroducing the Cyber Security News Industry Reactions to Govt Requiring Security Guarantees From Software Vendors.... September 16, 2022 Cyber Security News
Ethical AI, Possibility or Pipe Dream?Introducing the Cyber Security News Ethical AI, Possibility or Pipe Dream?.... September 12, 2022 Cyber Security News
Vulnerability in BackupBuddy Plugin Exploited to Hack WordPress SitesIntroducing the Cyber Security News Vulnerability in BackupBuddy Plugin Exploited to Hack WordPress Sites.... September 12, 2022 Cyber Security News
NIST Finalizes Cybersecurity Guidance for Ground Segment of Space OperationsIntroducing the Cyber Security News NIST Finalizes Cybersecurity Guidance for Ground Segment of Space Operations.... January 4, 2023 Cyber Security News
Web Security Company Detectify Raises $10 MillionIntroducing the Cyber Security News Web Security Company Detectify Raises $10 Million.... October 4, 2022 Cyber Security News