Vulnerability in Acer Laptops Allows Attackers to Disable Secure Boot By Orbit Brain November 29, 2022 0 182 viewsCyber Security News House › Endpoint SafetyVulnerability in Acer Laptops Permits Attackers to Disable Safe BootBy Ionut Arghire on November 29, 2022TweetA vulnerability impacting a number of Acer laptop computer fashions might enable an attacker to disable the Safe Boot characteristic and bypass safety protections to put in malware.Tracked as CVE-2022-4020 (CVSS rating of 8.1), the vulnerability was recognized within the HQSwSmiDxe DXE driver, which checks for the existence of the ‘BootOrderSecureBootDisable’ NVRAM variable to disable Safe Boot.“Vulnerability within the HQSwSmiDxe DXE driver on some shopper Acer Pocket book gadgets might enable an attacker with elevated privileges to change UEFI Safe Boot settings by modifying an NVRAM variable,” a Nationwide Vulnerability Database advisory explains.Acer explains that the vulnerability might enable an attacker to tamper with Safe Boot settings just by creating NVRAM variables. As a result of the affected firmware driver solely checks for the existence of the variables, their precise worth just isn’t essential.“By disabling the Safe Boot characteristic, an attacker can load their very own unsigned malicious bootloader to permit absolute management over the OS loading course of. This may enable them to disable or bypass protections to silently deploy their very own payloads with the system privileges,” Acer notes.Impacted system fashions, the pc maker says, embody Aspire A315-22, A115-21, and A315-22G, and Extensa EX215-21 and EX215-21G.“Acer is engaged on a BIOS replace to resolve this concern that can be posted on the Acer Help website. Acer recommends updating your BIOS to the most recent model to resolve this concern. This replace can be included as a essential Home windows replace,” the corporate notes.ESET safety researcher Martin Smolar was credited for locating and reporting the vulnerability.In response to ESET, this concern is like CVE-2022-3431, a vulnerability within the DXE driver BootOrderDxe of some Lenovo laptops which, simply because the HQSwSmiDxe DXE driver, checks for the existences of a BootOrderSecureBootDisable variable and disables Safe Boot if it exists.ESET warned of this Lenovo bug in early November, urging customers to replace the BIOS on impacted gadgets as quickly as doable.Now, the cybersecurity firm is elevating the alarm on this Acer vulnerability, urging customers to maintain an eye fixed out for the patches.“Along with Lenovo vulnerabilities we disclosed earlier this month, we found one other related vulnerability in Acer laptops. Similar as in Lenovo case, it permits deactivating UEFI Safe Boot by creating NVRAM variable instantly from OS,” ESET notes.Associated: Lenovo Patches UEFI Code Execution Vulnerability Affecting Many LaptopsAssociated: HP Patches UEFI Vulnerabilities Affecting Over 200 Computer systemsAssociated: Excessive-Severity UEFI Vulnerabilities Patched in Dell Enterprise LaptopsGet the Day by day Briefing Most CurrentMost LearnRansomware Gang Takes Credit score for Maple Leaf Meals HackVulnerability in Acer Laptops Permits Attackers to Disable Safe BootCybercriminals Promoting Entry to Networks Compromised by way of Current Fortinet VulnerabilityOracle Fusion Middleware Vulnerability Exploited within the WildCensus Bureau Chief Defends New Privateness Device In opposition to CriticsVirginia County Confirms Private Info Stolen in Ransomware AssaultMission Zero Flags ‘Patch Hole’ Issues on AndroidIrish Regulator Fines Meta 265 Million Euros Over Information BreachHack-for-Rent Group Targets Android Customers With Malicious VPN AppsCrackdown on African Cybercrime Results in Arrests, Infrastructure TakedownSearching for Malware in All of the Unsuitable Locations?First Step For The Web’s subsequent 25 years: Including Safety to the DNSTattle Story: What Your Laptop Says About YouBe in a Place to Act By way of Cyber Situational ConsciousnessReport Exhibits Closely Regulated Industries Letting Social Networking Apps Run Rampant2010, A Nice Yr To Be a Scammer.Do not Let DNS be Your Single Level of FailureLearn how to Establish Malware in a BlinkDefining and Debating Cyber WarfareThe 5 A’s that Make Cybercrime so EnticingLearn how to Defend In opposition to DDoS AssaultsSafety Budgets Not in Line with ThreatsAnycast – Three Causes Why Your DNS Community Ought to Use ItThe Evolution of the Prolonged Enterprise: Safety Methods for Ahead Considering OrganizationsUtilizing DNS Throughout the Prolonged Enterprise: It’s Dangerous Enterprise Acer bios CVE-2022-4020 disable Secure Boot UEFI vulnerability Orbit Brainhttp://orbitbrain.com/ Orbit Brain is the senior science writer and technology expert. Our aim provides the best information about technology and web development designing SEO graphics designing video animation tutorials and how to use software easy waysand much more. Like Best Service Latest Technology, Information Technology, Personal Tech Blogs, Technology Blog Topics, Technology Blogs For Students, Futurism Blog.
HYAS Unveils New Tool for Continuous DNS MonitoringIntroducing the Cyber Security News HYAS Unveils New Tool for Continuous DNS Monitoring.... August 8, 2022 Cyber Security News
Zero-Day Vulnerability Exploited to Hack Over 1,000 Zimbra Email ServersIntroducing the Cyber Security News Zero-Day Vulnerability Exploited to Hack Over 1,000 Zimbra Email Servers.... August 12, 2022 Cyber Security News
Jira Align Vulnerabilities Exposed Atlassian Infrastructure to AttacksIntroducing the Cyber Security News Jira Align Vulnerabilities Exposed Atlassian Infrastructure to Attacks.... October 25, 2022 Cyber Security News
Musk’s Latest Reason to Drop Twitter Deal – Whistleblower PaymentIntroducing the Cyber Security News Musk’s Latest Reason to Drop Twitter Deal – Whistleblower Payment.... September 10, 2022 Cyber Security News
API Security Firm FireTail Raises $5 MillionIntroducing the Cyber Security News API Security Firm FireTail Raises $5 Million.... December 16, 2022 Cyber Security News
Google Introduces New Capabilities for Cloud Armor Web Security ServiceIntroducing the Cyber Security News Google Introduces New Capabilities for Cloud Armor Web Security Service.... June 28, 2022 Cyber Security News