
Gigabyte Motherboards Sold with Firmware Backdoor, Millions Affected.
Researchers at Eclypsium have discovered a vulnerability in Gigabyte motherboards that could allow attackers to infect Windows PCs with malware. The vulnerability is related to the way Gigabyte implemented its App Center utility, which is supposed to keep firmware, drivers, and related software up to date. The firmware writes a Windows program that's embedded in the firmware to disk as GigabyteUpdateService.exe in the OS's system32 folder, and runs it. If an attacker intercepts the download and replaces the fetched code with malicious programs, they could achieve code execution on the victim's Windows box and commandeer it. Eclypsium has a list of 271 affected motherboards.