Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

LogoFAIL

From Wikipedia, the free encyclopedia
This articlemay be too technical for most readers to understand. Pleasehelp improve it tomake it understandable to non-experts, without removing the technical details.(May 2024) (Learn how and when to remove this message)
Vulnerability in computer motherboard firmware
LogoFAIL
CVE identifier(s)CVE-2023-40238
DiscovererBinarly
Affected hardwareMotherboard firmware withTianoCore EDK II, includingInsyde InsydeH2O, AMI Aptio, and Phoenix SCT firmware

LogoFAIL is asecurity vulnerability andexploit thereof that affects computer motherboard firmware withTianoCore EDK II, includingInsyde Software's InsydeH2O modules and similar code in AMI and Phoenix firmware, which are commonly found on bothIntel andAMD motherboards, and which enable loading of custom boot logos. The exploit was discovered in December 2023 by researchers atBinarly.[1][2]

Description

[edit]

The vulnerability exists when the Driver Execution Environment (DXE) is active after a successful Power On Self Test (POST) in theUEFI firmware (also known as the BIOS). The UEFI's boot logo is replaced with the exploit payload at this point, and the exploit can then take control of the system.[2]

Patches

[edit]

Intel patched the issue inIntel Management Engine (ME) version 16.1.30.2307 in December 2023. AMD addressed the problem in AGESA version 1.2.0.b, although some motherboard manufacturers did not include the fix under AGESA 1.2.0.c.[3]

External links

[edit]

References

[edit]
  1. ^Dan Goodin (December 6, 2023)."Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attack". Ars Technica.
  2. ^abRoshan Ashraf Shaikh (December 6, 2023)."LogoFAIL exploit bypasses hardware and software security measures and is nearly impossible to detect or remove". Ars Technica.
  3. ^Roshan Ashraf Shaikh (April 10, 2024)."AMD motherboard partners start rolling out BIOS updates with LogoFAIL bugfix". Tom's Hardware.
Hacking in the 2020s
← 2010sTimeline2030s →
Major incidents
2020
2021
2022
2023
2024
Groups
Individuals
Majorvulnerabilities
publiclydisclosed
Malware
2020
2021
2022


Stub icon

Thiscomputer security article is astub. You can help Wikipedia byexpanding it.

Retrieved from "https://en.wikipedia.org/w/index.php?title=LogoFAIL&oldid=1255111554"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2025 Movatter.jp