Handpicked best-sellers, trusted quality, and savings you deserve

New UEFI Firmware Flaw Exposes Common Motherboards To Assaults

Cybersecurity specialists simply discovered a flaw in the UEFI firmware that many fashionable motherboards use. The “bug” might let attackers do direct reminiscence entry (DMA) assaults on programs, which can allow unauthorized customers to realize deep and protracted entry to affected programs beneath sure circumstances, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.

To present you context, the PC motherboard incorporates low-level software program referred to as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} parts. One in all its main safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s supposed to safeguard system reminiscence. If arrange appropriately, the IOMMU stops exterior units from studying or writing to random components of system RAM.

Elements equivalent to PCIe growth playing cards, Thunderbolt peripherals, GPUs, and comparable {hardware} that may entry reminiscence instantly with out passing via the CPU are included in DMA-capable units. Malicious or compromised {hardware} can have much less of an affect as a result of these units are restricted to explicit reminiscence areas if the IOMMU is operational and correctly initialized.

The lately found vulnerability is brought on by the incorrect manner this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, though the IOMMU was by no means totally or appropriately arrange, after which the working system consequently assumes that reminiscence protections are carried out, though they aren’t actively enforced.

The problem is being tracked beneath a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options in another way.

Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, have been the primary ones to establish the vulnerability. Vanguard, Riot’s anti-cheat system, is carried out on the kernel stage and incorporates safeguards which can be supposed to stop unauthorized system manipulation. Valorant could also be prevented from launching on programs which can be affected by this particular flaw, as it detects an unsafe {hardware} safety state.

There’s an essential limitation to consider, though the attainable impact might be horrible: the power to bodily entry the system and join a malicious PCIe or comparable machine earlier than the working system boots up are conditions for a DMA assault. Consequently, the likelihood of widespread exploitation is considerably diminished, significantly for residential customers.

Customers are being suggested to monitor updates from their motherboard producers and apply any obtainable firmware patches. Updating the UEFI firmware remains to be important to preserving system safety, significantly in mild of the continued evolution of hardware-level assaults.

Filed in Computers. Learn extra about , , , and .

Trending Merchandise

- 42% Vetroo AL900 ATX PC Case with 270Â...
Original price was: $155.68.Current price is: $89.99.

Vetroo AL900 ATX PC Case with 270Â...

0
Add to compare
- 37% ASUS TUF Gaming GT502 ATX Full Towe...
Original price was: $268.58.Current price is: $169.99.

ASUS TUF Gaming GT502 ATX Full Towe...

0
Add to compare
- 41% AULA Keyboard, T102 104 Keys Gaming...
Original price was: $42.99.Current price is: $25.49.

AULA Keyboard, T102 104 Keys Gaming...

0
Add to compare
- 43% HP 14″ Ultral Light Laptop fo...
Original price was: $437.48.Current price is: $249.99.

HP 14″ Ultral Light Laptop fo...

0
Add to compare
- 31% HP 14″ HD Laptop | Back to Sc...
Original price was: $560.16.Current price is: $389.00.

HP 14″ HD Laptop | Back to Sc...

0
Add to compare
- 28% NETGEAR Nighthawk Tri-Band WiFi 6E ...
Original price was: $399.99.Current price is: $288.04.

NETGEAR Nighthawk Tri-Band WiFi 6E ...

0
Add to compare
- 44% Logitech MK955 Signature Slim Wi-fi...
Original price was: $178.98.Current price is: $99.99.

Logitech MK955 Signature Slim Wi-fi...

0
Add to compare
- 13% Wireless Keyboard and Mouse Combo &...
Original price was: $45.99.Current price is: $39.99.

Wireless Keyboard and Mouse Combo &...

0
Add to compare
- 32% Lenovo V15 Laptop, 15.6″ FHD ...
Original price was: $720.76.Current price is: $487.00.

Lenovo V15 Laptop, 15.6″ FHD ...

0
Add to compare
- 33% Logitech MK235 Wi-fi Keyboard and M...
Original price was: $35.99.Current price is: $23.99.

Logitech MK235 Wi-fi Keyboard and M...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

GoodPricePicks
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart