DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

New Firmware Attacks: Taking Advantage of Carelessness

DigitalCIO Bureau by DigitalCIO Bureau
December 8, 2023
in Tech News
0
New Firmware Attacks: Taking Advantage of Carelessness
75
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Finding and reporting vulnerabilities is basically the primary activity of Binarly Research Team. A small research project on LogoFAIL, which was picked up by them just to have some fun, turned into a mammoth industry-wide disclosure and uncovered massive flaws.

While organizations are implementing different security solutions at different scales & levels and globally security vendors are advancing their security products and solutions almost every day, likewise new discoveries of vulnerabilities are also being reported at a much higher speed. The recent findings on LogoFAIL project have disclosed severe vulnerabilities, which eventually can allow hackers to hijack the execution flow and bypass security features like Secure Boot, including hardware-based Verified Boot mechanisms.

The Rationale Behind The LogoFAIL Project

The very basic thought behind this entire project for Binarly research team was ‘What if the graphic image parsers embedded into system firmware do not update frequently and use not only outdated but also customized versions of the common image parsing libraries?’

The team delved deeper into this wormhole and were shocked by multiple high-impact discoveries that could be used by threat actors to deliver a malicious payload and bypass Secure Boot, Intel Boot Guard, and other security technologies by design. More importantly, it can open doors for attackers to bypass modern endpoint security solutions and should be considered much more powerful than the recent BlackLotus bootkit.

According to team, one of the most important discoveries was that LogoFAIL is not silicon-specific and can impact x86 and ARM-based devices. LogoFAIL is UEFI and IBV-specific because of the specifics of vulnerable image parsers that have been used. That shows a much broader impact from the perspective of the discoveries that will be presented on Dec 6th.

LogoFAIL’s Work Process

The vulnerabilities allow attackers to store malicious logo images either on the EFI System Partition (ESP) or inside unsigned sections of a firmware update. When these images are parsed during boot, the vulnerability can be triggered and an attacker-controlled payload can arbitrarily be executed to hijack the execution flow and bypass security features like Secure Boot, including hardware-based Verified Boot mechanisms (like Intel Boot Guard, AMD Hardware-Validated Boot or ARM TrustZone-based Secure Boot).

These vulnerabilities can compromise the entire system’s security, rendering “below-the-OS” security measures like any shade of Secure Boot ineffective, including Intel Boot Guard. This level of compromise means attackers can gain deep control over the affected systems.

The team previously had seen attackers abusing ESP partitions multiple times to modify operating system-related bootloaders to deliver UEFI bootkits (including BlackLotus). The LogoFAIL case creates a different perspective on the ESP partition attack surface with data-only exploitation by modifying the logo image.

Affected People & Organizations

Hundreds of consumer and enterprise-grade devices from various vendors, including Intel, Acer, and Lenovo, are potentially vulnerable. The exact list of affected devices is still being determined but it’s crucial to note that all three major IBVs are impacted — AMI, Insyde, and Phoenix due to multiple security issues related to image parsers they are shipping as a part of their firmware. Based on this reference code impact, we estimate LogoFAIL impacts almost any device powered by these vendors in one way or another. Also, it’s not limited to specific hardware and can be successfully exploited on x86 or ARM-based devices.

The types — and sheer volume — of security vulnerabilities discovered by Binarly show pure product security maturity and code quality in general on IBVs reference code. Most of these companies grew up in the early 90s. They never change their mindset, being more proactive than reactive and fixing only known problems without addressing complete attack surfaces or implementing effective mitigations.

Easy To Avoid

These types of attacks can be avoided if graphic image parsers embedded into system firmware can be updated frequently and use only updated versions. Hence, it is proven that vulnerabilities will stay here in the world of digital device forever and the one of the most recommended ways to mitigate attacks upgrading the systems in regular intervals.

Source: Binarly Research Page

 

Tags: Firmware
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

CrowdStrike and Schwarz Digits Expand Strategic Partnership to Deliver Sovereign Cybersecurity Across Europe

by DigitalCIO Bureau
July 17, 2026
0
CrowdStrike and Schwarz Digits Expand Strategic Partnership to Deliver Sovereign Cybersecurity Across Europe

CrowdStrike to acquire XM Cyber intellectual property and provide customers a pathway to exposure management on the CrowdStrike Falcon platform; Schwarz Digits to adopt the Falcon platform and...

Read moreDetails

Rapidise Appoints Hardik Shah as Senior Director – Solution Engineering to Strengthen IoT ODM Growth

by DigitalCIO Bureau
July 17, 2026
0
Rapidise Appoints Hardik Shah as Senior Director – Solution Engineering to Strengthen IoT ODM Growth

Hardik will lead solution engineering for Rapidise’s IoT ODM business, backed by over 22 years of experience in semiconductors, IoT and wireless technologies Rapidise has appointed Hardik Shah as...

Read moreDetails

TCS and Google Cloud launch Gemini Experience Center in Kolkata

by DigitalCIO Bureau
July 16, 2026
0
TCS and Google Cloud launch Gemini Experience Center in Kolkata

Focused on the Consumer Business Group (CBG) vertical, the Kolkata Gemini Experience Center will accelerate the adoption of agentic AI. The facility marks TCS’ eighth Gemini Experience Center...

Read moreDetails

TCS Launches Industrial AI Solutions Lab in Bengaluru Powered by NVIDIA

by DigitalCIO Bureau
July 15, 2026
0
TCS Launches Industrial AI Solutions Lab in Bengaluru Powered by NVIDIA

New Physical AI facility at TCS Global Axis Campus will accelerate AI-led mobility and industrial solutions using NVIDIA AI Infrastructure Tata Consultancy Services (TCS) today announced the launch...

Read moreDetails

Vi brings 24X7 Live Darshan of Shree Jagannath Rath Yatra 2026 on Vi Movies & TV

by DigitalCIO Bureau
July 15, 2026
0
Vi brings 24X7 Live Darshan of Shree Jagannath Rath Yatra 2026 on Vi Movies & TV

Vi customers anywhere in India can view Live Relay of the 12 Day Rath Yatra festivities, directly from Puri As Lord Jagannath, Lord Balabhadra and Devi Subhadra prepare...

Read moreDetails
Next Post
Barracuda Announces New Global Partner Program

Barracuda Announces New Global Partner Program

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

New Firmware Attacks: Taking Advantage of Carelessness

New Firmware Attacks: Taking Advantage of Carelessness

December 8, 2023
Gartner: Worldwide IT Spending to Grow 8% in 2024

Gartner: Worldwide IT Spending to Grow 8% in 2024

October 20, 2023
Infosys and NVIDIA Team to Boost Productivity With Generative AI

Infosys and NVIDIA Team to Boost Productivity With Generative AI

September 21, 2023

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Accenture Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Collaboration CrowdStrike Cybersecurity Digital Transformation E-books Enterprises Fortinet Gartner Generative AI Google Cloud HCLTech IBM India Infographics Infosys Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Partnership Sophos Strategic Partnership Tata Consultancy Services TCS Tenable Trend Micro Veeam Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?