Gigabyte Motherboards Vulnerable to Backdoor Hacking Threat

1 min read
Source: Naked Security
TL;DR Summary

Researchers at Eclypsium have discovered a vulnerability in Gigabyte motherboards that could allow cybercriminals to abuse the system. The issue is with a Gigabyte service called APP Center, which allows users to download apps, drivers and BIOS firmware. The problem is with a component called GigabyteUpdateService.exe, which fetches and runs software from three hard-wired URLs, one of which uses plain old HTTP, providing no cryptographic integrity protection during the download. The other two URLs use HTTPS, but the update utility doesn't verify the HTTPS certificate that the server at the other end sends back.

Share this article

Reading Insights

Total Reads

0

Unique Readers

10

Time Saved

7 min

vs 8 min read

Condensed

94%

1,59094 words

Want the full story? Read the original article

Read on Naked Security