Gigabyte Motherboards Sold with Firmware Backdoor, Millions Affected.

Researchers at Eclypsium have discovered a vulnerability in Gigabyte motherboards that could allow attackers to infect Windows PCs with malware. The vulnerability is related to the way Gigabyte implemented its App Center utility, which is supposed to keep firmware, drivers, and related software up to date. The firmware writes a Windows program that's embedded in the firmware to disk as GigabyteUpdateService.exe in the OS's system32 folder, and runs it. If an attacker intercepts the download and replaces the fetched code with malicious programs, they could achieve code execution on the victim's Windows box and commandeer it. Eclypsium has a list of 271 affected motherboards.
- Millions of Gigabyte PC motherboards backdoored? What's the actual score? The Register
- Millions of PC motherboards were sold with a firmware backdoor Ars Technica
- Firmware Backdoor Discovered in Gigabyte Motherboards, 250+ Models Affected Tom's Hardware
- Gigabyte shipped millions of motherboards with a dangerous firmware backdoor BGR
- Potential Backdoor in Gigabyte PCs Exposes Supply Chain Risks Infosecurity Magazine
Reading Insights
0
11
3 min
vs 4 min read
86%
724 → 104 words
Want the full story? Read the original article
Read on The Register