Vietnam.vn - Nền tảng quảng bá Việt Nam

A series of 'big guys' have security holes because of UEFI popularity

Báo Thanh niênBáo Thanh niên18/01/2024


According to ITNews , Quarkslab warned that these security holes can be exploited by unauthenticated remote attackers on the same local network, and in some cases, even remotely. The researchers said the impacts of these vulnerabilities include DDoS, information leakage, remote code execution, DNS cache poisoning, and network session hijacking.

Một loạt 'ông lớn' dính lỗ hổng bảo mật vì UEFI phổ biến- Ảnh 1.

UEFI is the most commonly used BIOS system.

The CERT Cybersecurity Coordination Center at Carnegie Mellon University (USA) said that this error was identified in the implementation process from UEFI vendors, including American Megatrends, Insyde Software, Intel and Phoenix Technologies, while Toshiba was not affected.

Insyde Software, AMI, and Phoenix Technologies have all confirmed to Quarkslab that they are providing fixes. Meanwhile, the bug is still being investigated by 18 other vendors, including big names like Google, HP, Microsoft, ARM, ASUSTek, Cisco, Dell, Lenovo, and VAIO.

The flaws reside in the EDK II TCP/IP stack, NetworkPkg, which is used for network booting and is particularly important in data centers and HPC environments for automating early boot phases. The three most severe flaws, all with CVSS scores of 8.3, are related to DCHPv6 handler buffer overflows, including CVE-2023-45230, CVE-2023-45234, and CVE-2023-45235. The other flaws have CVSS scores ranging from 5.3 to 7.5.



Source link

Comment (0)

No data
No data

Same tag

Same category

Phu Quoc - a vacation that awakens the senses
Why is the upcoming Vietnamese blockbuster 'Snow White' receiving a strong reaction from the audience?
Phu Quoc in top 10 most beautiful islands in Asia
People's Artist Thanh Lam is grateful to her doctor husband, and "corrects" herself thanks to marriage

Same author

Heritage

Figure

Business

No videos available

News

Political System

Local

Product