Software bugs and security issues can be found at any time. But rarely do they are found in bulk.
Binarly, a security research company, has disclosed vulnerabilities affecting InsydeH2O "Hardware-2-Operating System" Unified Extensible Firmware Interface (UEFI) BIOS, a firmware used by "several of the major enterprise vendor ecosystems."
The issue was mostly found in the System Management Mode (SMM), which is responsible for providing system-wide power management and hardware control features.
Most of the flaws are of the SMM Memory Corruption variety, as well as SMM Callout (Privilege Escalation) and DXE Memory Corruption.
In total, there are at least 23 such vulnerabilities have been found affecting a number of the world's major industry vendors like Microsoft, Intel, HP, Dell, Lenovo, Siemens, Fujitsu, among others.
All of the affected vendors are the ones that had adopted the Independent BIOS Developers (IBV) code into their UEFI firmware.

According to Binarly in a blog post:
By exploiting these vulnerabilities, attackers can successfully install malware that survives operating system re-installations and allows the bypass of endpoint security solutions (EDR/AV), Secure Boot and Virtualization-Based Security isolation.
The active exploitation of all the discovered vulnerabilities can’t be detected by firmware integrity monitoring systems due to limitations of the Trusted Platform Module (TPM) measurement. The remote device health attestation solutions will not detect the affected systems due to the design limitations in visibility of the firmware runtime.
Binarly first discovered the vulnerabilities on Fujitsu's LIFEBOOK notebooks but quickly realized that other vendors, like those mentioned above, were also susceptible to these issues as they were also utilizing InsydeH2O UEFI solutions.
UEFI provider Insyde Software said it worked with Binarly to resolve the issues, and has released firmware updates to patch the bugs.
"We are extremely thankful for Binarly's work in discovering the items outlined in today's published security disclosures," said Tim Lewis, CTO at Insyde Software in a blog post.
"We appreciated Insyde Software's prompt and professional response to the results of our analysis on their firmware," said Alex Matrosov, Founder and CEO of Binarly.

The vulnerabilities are tracked as:
CVE-2020-27339, CVE-2020-5953, CVE-2021-33625, CVE-2021-33626, CVE-2021-33627, CVE-2021-41837, CVE-2021-41838, CVE-2021-41839, CVE-2021-41840,CVE-2021-41841, CVE-2021-42059, CVE-2021-42060, CVE-2021-42113, CVE-2021-42554, CVE-2021-43323, CVE-2021-43522, CVE-2021-43615, CVE-2021-45969, CVE-2021-45970, CVE-2021-45971, CVE-2022-24030, CVE-2022-24031, and CVE-2022-24069.
The issues have been evaluated as severe due to the fact that they allow hackers to have higher privileges than those of the operating system's kernel in affected systems.
What's more, the vulnerabilities allow malware to bypass or invalidate hardware security features like Secure Boot, Intel BootGuard, and Virtualization-Based Security
In other words, malware can be written to take advantage of these vulnerabilities to easily survive operating system re-installation and evade traditional endpoint security solutions like antivirus software and managed Endpoint Detection and Response (EDR).
Successful exploitation may lead to persistent malware that may be almost impossible to get rid of.
While the patch has been created, it's up to the end users on how quickly the patch is installed.



















































































































































































































































































































































































