Gigabyte Motherboards Vulnerable to Backdoor Hacking Threat
TL;DR Summary
Researchers at Eclypsium have discovered a vulnerability in Gigabyte motherboards that could allow cybercriminals to abuse the system. The issue is with a Gigabyte service called APP Center, which allows users to download apps, drivers and BIOS firmware. The problem is with a component called GigabyteUpdateService.exe, which fetches and runs software from three hard-wired URLs, one of which uses plain old HTTP, providing no cryptographic integrity protection during the download. The other two URLs use HTTPS, but the update utility doesn't verify the HTTPS certificate that the server at the other end sends back.
- Researchers claim Windows “backdoor” affects hundreds of Gigabyte motherboards Naked Security
- If you have a Gigabyte motherboard, your PC might stealthily download malware Digital Trends
- Check if your motherboard is on new Gigabyte malware list PCGamesN
- Gigabyte Firmware Exposes Millions Of Motherboards To Backdoor Hacking Threat Hot Hardware
- Gigabyte Motherboards Widely Exposed To A Hidden Backdoor, Company Rushes To Issue BIOS Fix Wccftech
Reading Insights
Total Reads
0
Unique Readers
10
Time Saved
7 min
vs 8 min read
Condensed
94%
1,590 → 94 words
Want the full story? Read the original article
Read on Naked Security