Vulnerability in Acer Laptops Allows Attackers to Disable Secure Boot By Orbit Brain November 29, 2022 0 209 views Cyber Security News House › Endpoint SafetyVulnerability in Acer Laptops Permits Attackers to Disable Safe BootBy Ionut Arghire on November 29, 2022TweetA vulnerability impacting a number of Acer laptop computer fashions might enable an attacker to disable the Safe Boot characteristic and bypass safety protections to put in malware.Tracked as CVE-2022-4020 (CVSS rating of 8.1), the vulnerability was recognized within the HQSwSmiDxe DXE driver, which checks for the existence of the ‘BootOrderSecureBootDisable’ NVRAM variable to disable Safe Boot.“Vulnerability within the HQSwSmiDxe DXE driver on some shopper Acer Pocket book gadgets might enable an attacker with elevated privileges to change UEFI Safe Boot settings by modifying an NVRAM variable,” a Nationwide Vulnerability Database advisory explains.Acer explains that the vulnerability might enable an attacker to tamper with Safe Boot settings just by creating NVRAM variables. As a result of the affected firmware driver solely checks for the existence of the variables, their precise worth just isn’t essential.“By disabling the Safe Boot characteristic, an attacker can load their very own unsigned malicious bootloader to permit absolute management over the OS loading course of. This may enable them to disable or bypass protections to silently deploy their very own payloads with the system privileges,” Acer notes.Impacted system fashions, the pc maker says, embody Aspire A315-22, A115-21, and A315-22G, and Extensa EX215-21 and EX215-21G.“Acer is engaged on a BIOS replace to resolve this concern that can be posted on the Acer Help website. Acer recommends updating your BIOS to the most recent model to resolve this concern. This replace can be included as a essential Home windows replace,” the corporate notes.ESET safety researcher Martin Smolar was credited for locating and reporting the vulnerability.In response to ESET, this concern is like CVE-2022-3431, a vulnerability within the DXE driver BootOrderDxe of some Lenovo laptops which, simply because the HQSwSmiDxe DXE driver, checks for the existences of a BootOrderSecureBootDisable variable and disables Safe Boot if it exists.ESET warned of this Lenovo bug in early November, urging customers to replace the BIOS on impacted gadgets as quickly as doable.Now, the cybersecurity firm is elevating the alarm on this Acer vulnerability, urging customers to maintain an eye fixed out for the patches.“Along with Lenovo vulnerabilities we disclosed earlier this month, we found one other related vulnerability in Acer laptops. Similar as in Lenovo case, it permits deactivating UEFI Safe Boot by creating NVRAM variable instantly from OS,” ESET notes.Associated: Lenovo Patches UEFI Code Execution Vulnerability Affecting Many LaptopsAssociated: HP Patches UEFI Vulnerabilities Affecting Over 200 Computer systemsAssociated: Excessive-Severity UEFI Vulnerabilities Patched in Dell Enterprise LaptopsGet the Day by day Briefing Most CurrentMost LearnRansomware Gang Takes Credit score for Maple Leaf Meals HackVulnerability in Acer Laptops Permits Attackers to Disable Safe BootCybercriminals Promoting Entry to Networks Compromised by way of Current Fortinet VulnerabilityOracle Fusion Middleware Vulnerability Exploited within the WildCensus Bureau Chief Defends New Privateness Device In opposition to CriticsVirginia County Confirms Private Info Stolen in Ransomware AssaultMission Zero Flags ‘Patch Hole’ Issues on AndroidIrish Regulator Fines Meta 265 Million Euros Over Information BreachHack-for-Rent Group Targets Android Customers With Malicious VPN AppsCrackdown on African Cybercrime Results in Arrests, Infrastructure TakedownSearching for Malware in All of the Unsuitable Locations?First Step For The Web’s subsequent 25 years: Including Safety to the DNSTattle Story: What Your Laptop Says About YouBe in a Place to Act By way of Cyber Situational ConsciousnessReport Exhibits Closely Regulated Industries Letting Social Networking Apps Run Rampant2010, A Nice Yr To Be a Scammer.Do not Let DNS be Your Single Level of FailureLearn how to Establish Malware in a BlinkDefining and Debating Cyber WarfareThe 5 A’s that Make Cybercrime so EnticingLearn how to Defend In opposition to DDoS AssaultsSafety Budgets Not in Line with ThreatsAnycast – Three Causes Why Your DNS Community Ought to Use ItThe Evolution of the Prolonged Enterprise: Safety Methods for Ahead Considering OrganizationsUtilizing DNS Throughout the Prolonged Enterprise: It’s Dangerous Enterprise Acer bios CVE-2022-4020 disable Secure Boot UEFI vulnerability Orbit Brainhttp://orbitbrain.com/ Orbit Brain is the senior science writer and technology expert. Our aim provides the best information about technology and web development designing SEO graphics designing video animation tutorials and how to use software easy ways and much more. Like Best Service Latest Technology, Information Technology, Personal Tech Blogs, Technology Blog Topics, Technology Blogs For Students, Futurism Blog.
‘MaliBot’ Android Malware Steals Financial, Personal InformationIntroducing the Cyber Security News ‘MaliBot’ Android Malware Steals Financial, Personal Information.... June 17, 2022 Cyber Security News
High-Profile Hacks Show Effectiveness of MFA Fatigue AttacksIntroducing the Cyber Security News High-Profile Hacks Show Effectiveness of MFA Fatigue Attacks.... September 28, 2022 Cyber Security News
CISA: Vulnerability in Delta Electronics ICS Software Exploited in AttacksIntroducing the Cyber Security News CISA: Vulnerability in Delta Electronics ICS Software Exploited in Attacks.... August 26, 2022 Cyber Security News
Meta Hit With 390 Million Euro Fine Over EU Data BreachesIntroducing the Cyber Security News Meta Hit With 390 Million Euro Fine Over EU Data Breaches.... January 5, 2023 Cyber Security News
New ‘RisePro’ Infostealer Increasingly Popular Among CybercriminalsIntroducing the Cyber Security News New ‘RisePro’ Infostealer Increasingly Popular Among Cybercriminals.... December 20, 2022 Cyber Security News
LastPass Says Source Code Stolen in Data BreachIntroducing the Cyber Security News LastPass Says Source Code Stolen in Data Breach.... August 26, 2022 Cyber Security News