Security News > 2022 > March > New Dell BIOS Bugs Affect Millions of Inspiron, Vostro, XPS, Alienware Systems
Five new security weaknesses have been disclosed in Dell BIOS that, if successfully exploited, could lead to code execution on vulnerable systems, joining the likes of firmware vulnerabilities recently uncovered in Insyde Software's InsydeH2O and HP Unified Extensible Firmware Interface.
"The active exploitation of all the discovered vulnerabilities can't be detected by firmware integrity monitoring systems due to limitations of the Trusted Platform Module measurement," firmware security company Binarly, which discovered the latter three flaws, said in a write-up.
"The remote device health attestation solutions will not detect the affected systems due to the design limitations in visibility of the firmware runtime."
All the flaws relate to improper input validation vulnerabilities affecting the System Management Mode of the firmware, effectively allowing a local authenticated attacker to leverage the system management interrupt to achieve arbitrary code execution.
System Management Mode refers to a special-purpose CPU mode in x86 microcontrollers that's designed for handling system-wide functions like power management, system hardware control, thermal monitoring, and other proprietary manufacturer-developed code.
Whenever one of these operations is requested, a non-maskable interrupt is invoked at runtime, which executes SMM code installed by the BIOS. Given that SMM code executes at the highest privilege level and is invisible to the underlying operating system, the method makes it ripe for abuse to deploy persistent firmware implants.
News URL
https://thehackernews.com/2022/03/new-dell-bios-bugs-affect-millions-of.html