Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks

UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks

Posted on December 18, 2025December 18, 2025 By CWS

Motherboards from a number of main distributors are affected by a vulnerability that may permit a risk actor to conduct early-boot assaults.

In response to an advisory printed on Wednesday by Carnegie Mellon College’s CERT/CC, an attacker can exploit the vulnerability to entry information in reminiscence or affect the preliminary state of the system.

The safety gap may permit an attacker to acquire delicate information and conduct pre-boot code injection. 

Whereas the difficulty could sound crucial because it undermines the integrity of the boot course of and permits assaults to be carried out previous to the working system’s defenses being loaded, exploitation requires bodily entry to the focused machine.

Particularly, an area attacker wants to have the ability to join a malicious PCI Specific (PCIe) machine to a pc with a weak motherboard.

[ Read: Intel, AMD Processors Affected by PCIe Vulnerabilities ]

ASRock, Asus, Gigabyte, and MSI have confirmed that a few of their motherboards are affected. Every vendor has launched its personal advisory to tell clients in regards to the vulnerability and the provision of firmware patches.

In response to the CERT/CC advisory, merchandise from AMD, AMI, Insyde, Intel, Phoenix Applied sciences, and Supermicro should not impacted. Over a dozen distributors presently have an ‘unknown’ standing. Commercial. Scroll to proceed studying.

Technical particulars

The vulnerability, described as a safety mechanism failure, is said to UEFI implementations and the Enter-Output Reminiscence Administration Unit (IOMMU), which is designed to forestall malicious reminiscence entry from peripheral gadgets.

The issue is that in the course of the boot course of the firmware signifies that direct reminiscence entry (DMA) protections are enabled, when in actuality the IOMMU is just not correctly configured and activated till instantly earlier than management is handed over to the working system.

This permits an attacker who has bodily entry to the focused system to make use of a malicious PCIe machine to conduct a DMA assault.

CERT/CC defined in its advisory: 

“In environments the place bodily entry can’t be absolutely managed or relied on, immediate patching and adherence to {hardware} safety greatest practices are particularly vital. As a result of the IOMMU additionally performs a foundational function in isolation and belief delegation in virtualized and cloud environments, this flaw highlights the significance of guaranteeing right firmware configuration even on programs not usually utilized in information facilities.”

The CVE identifiers CVE-2025-11901, CVE-2025‑14302, CVE-2025-14303, and CVE-2025-14304 have been assigned to the vulnerability.

The difficulty was responsibly disclosed by researchers from Riot Video games.

Associated: Patch Bypassed for Supermicro Vulnerability Permitting BMC Hack

Associated: Flaw in Industrial Laptop Maker’s UEFI Apps Permits Safe Boot Bypass on Many Units

Associated: MITRE Updates Checklist of Most Widespread {Hardware} Weaknesses

Security Week News Tags:Attacks, EarlyBoot, Enables, Major, Motherboards, UEFI, Vulnerability

Post navigation

Previous Post: HPE Patches Critical Flaw in IT Infrastructure Management Software
Next Post: New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector

Related Posts

Australian Man Sentenced to Prison for Wi-Fi Attacks at Airports and on Flights Australian Man Sentenced to Prison for Wi-Fi Attacks at Airports and on Flights Security Week News
US Seizes .8 Million From Zeppelin Ransomware Operator US Seizes $2.8 Million From Zeppelin Ransomware Operator Security Week News
Latest Android Update Fixes Zero-Day and 123 Vulnerabilities Latest Android Update Fixes Zero-Day and 123 Vulnerabilities Security Week News
Google and FBI Halt Major Proxy Network Using Millions of Devices Google and FBI Halt Major Proxy Network Using Millions of Devices Security Week News
Senator Urges FTC Probe of Microsoft Over Security Failures Senator Urges FTC Probe of Microsoft Over Security Failures Security Week News
Hackers Start Exploiting Critical Cisco ISE Vulnerabilities Hackers Start Exploiting Critical Cisco ISE Vulnerabilities Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FastNetMon Unveils Netomics for Enhanced Routing Control
  • Hackers Exploit Fake Microsoft Passkey Enrollment for Attacks
  • Top Unified Threat Management Solutions in 2026
  • Study Reveals Security Flaws in Free Android VPN Apps
  • WhatsApp Exploit Turns OpenClaw into Hacker Tool

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FastNetMon Unveils Netomics for Enhanced Routing Control
  • Hackers Exploit Fake Microsoft Passkey Enrollment for Attacks
  • Top Unified Threat Management Solutions in 2026
  • Study Reveals Security Flaws in Free Android VPN Apps
  • WhatsApp Exploit Turns OpenClaw into Hacker Tool

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark