New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards
A security flaw in some motherboard models from manufacturers such as ASRock, ASUSTeK Computer, GIGABYTE, and MSI makes them vulnerable to early-boot direct memory access (DMA) attacks in architectures that use input-output memory management units (IOMMU) and Unified Extensible Firmware Interface (UEFI).
DMA-capable devices can change or examine system memory prior to the loading of the operating system since UEFI and IOMMU are built to impose a security foundation and stop peripherals from executing illegal memory accesses.
A difference in the DMA protection state is the cause of the vulnerability, which was found in some UEFI implementations by Nick Peterson and Mohamed Al-Sharifi of Riot Games. The firmware fails to setup and activate the IOMMU at the crucial startup step, even i...


