Fri. Apr 26th, 2024

All the modern version of Windows are affected by firmware driver vulnerability and this information was revealed at  the DEF CON hacker convention. The researcher have found a common design flaw within the hardware device drivers from the multiple vendors including Huawei, Intel, NVIDIA, Realtek Semiconductor, SuperMicro and Toshiba. The total number of hardware vendors that are affected flaw by this goes up to 20 and it also includes the major BIOS vendor. The nature of the vulnerability has the potential for the widespread compromise of Windows 10 machine.

Eclypsium’s research team were investigating how insecure drivers can be abused to attack a device and gain a foothold on the system it is part of. “Drivers that provide access to system BIOS or system components for the purposes of updating firmware, running diagnostics, or customizing options on the component,” the researchers stated during their presentation, “can allow attackers to turn the very tools used to manage a system into powerful threats that can escalate privileges and persist invisibly on the host.”

The drivers were found to have design flaws that enable what are meant to be “low-privilege” applications to be used by a threat actor in such a way as to potentially compromise parts of the Windows operating system that should only be accessible by “privileged” applications. That includes the Windows kernel at the very heart of the operating system.

Has the problem been fixed yet?

Mickey Shkatov, a principal researcher at Eclypsium, told zDNet that “Some vendors, like Intel and Huawei, have already issued updates.” Others, which are independent BIOS vendors, like Phoenix and Insyde, “are releasing their updates to their customer OEMs,” Shkatov said.

The Eclypsium research reveals that the security issue applies to “all modern versions of Microsoft Windows,” and “there is currently no universal mechanism to keep a Windows machine from loading one of these known bad drivers.” That said, group policies for Windows Enterprise, Pro and Sever could provide a degree of mitigation to “a subset of users,” the researchers stated

Microsoft suggests some Prevention :

A Microsoft statement said, “In order to exploit vulnerable drivers, an attacker would need to have already compromised the computer. To help mitigate this class of issues, Microsoft recommends that customers use Windows Defender Application Control to block known vulnerable software and drivers.” As well as turning on memory integrity for capable devices in Windows Security, Microsoft also recommended using Windows 10 and the Edge browser “for the best protection.”

Leave a Reply

Your email address will not be published. Required fields are marked *