EVGA

Intel SPI Flash Flaw Lets Attackers Alter or Delete BIOS/UEFI Firmware

Author
rjohnson11
EVGA Forum Moderator
  • Total Posts : 85038
  • Reward points : 0
  • Joined: 10/5/2004
  • Location: Netherlands
  • Status: offline
  • Ribbons : 86
Tuesday, April 17, 2018 4:41 PM (permalink)
https://www.bleepingcomputer.com/news/security/intel-spi-flash-flaw-lets-attackers-alter-or-delete-bios-uefi-firmware/
 
The vulnerability affects all Intel processors dating all the way back to 5th generation "Broadwell." The company quietly passed on fixes to its OEM partners to release as BIOS updates. So the vulnerability was spotted and a fix given to OEMs to employ it on their motherboards. Looks to me like Intel kept this quiet until a fix was passed on.

AMD Ryzen 9 7950X,  Corsair Mp700 Pro M.2, 64GB Corsair Dominator Titanium DDR5  X670E Steel Legend, MSI RTX 4090 Associate Code: H5U80QBH6BH0AXF. I am NOT an employee of EVGA

#1

4 Replies Related Threads

    Cool GTX
    EVGA Forum Moderator
    • Total Posts : 31353
    • Reward points : 0
    • Joined: 12/12/2010
    • Location: Folding for the Greater Good
    • Status: offline
    • Ribbons : 123
    Re: Intel SPI Flash Flaw Lets Attackers Alter or Delete BIOS/UEFI Firmware Tuesday, April 17, 2018 5:09 PM (permalink)

    Learn your way around the EVGA Forums, Rules & limits on new accounts Ultimate Self-Starter Thread For New Members

    I am a Volunteer Moderator - not an EVGA employee

    Older RIG projects RTX Project  Nibbler


     When someone does not use reason to reach their conclusion in the first place; you can't use reason to convince them otherwise!
    #2
    rjohnson11
    EVGA Forum Moderator
    • Total Posts : 85038
    • Reward points : 0
    • Joined: 10/5/2004
    • Location: Netherlands
    • Status: offline
    • Ribbons : 86
    Re: Intel SPI Flash Flaw Lets Attackers Alter or Delete BIOS/UEFI Firmware Tuesday, April 17, 2018 7:11 PM (permalink)
    Cool GTX
    Related Intel security advisory INTEL-SA-00087
     
     


    Yep, that is what I thought. Intel kept this low key until a patch was ready.

    AMD Ryzen 9 7950X,  Corsair Mp700 Pro M.2, 64GB Corsair Dominator Titanium DDR5  X670E Steel Legend, MSI RTX 4090 Associate Code: H5U80QBH6BH0AXF. I am NOT an employee of EVGA

    #3
    Hoggle
    EVGA Forum Moderator
    • Total Posts : 8899
    • Reward points : 0
    • Joined: 10/14/2003
    • Location: Eugene, OR
    • Status: offline
    • Ribbons : 4
    Re: Intel SPI Flash Flaw Lets Attackers Alter or Delete BIOS/UEFI Firmware Tuesday, April 17, 2018 7:38 PM (permalink)
    Well I for one am glad they kept it low key until a patch was released. If they announced the flaw before a fix was ready we would see it quickly exploited in the real world.

    Use an Associates Code & SAVE 5% - 10% on your purchase. Just click on the associates banner to save, or enter the associates code at checkout on your next purchase. If you choose to use my code I want to personally say "Thank You" for using it. 
     
     
    #4
    howdyho1
    Superclocked Member
    • Total Posts : 236
    • Reward points : 0
    • Joined: 12/1/2009
    • Location: near the mountains
    • Status: offline
    • Ribbons : 1
    Re: Intel SPI Flash Flaw Lets Attackers Alter or Delete BIOS/UEFI Firmware Tuesday, April 17, 2018 8:08 PM (permalink)
    rjohnson11
     
    Yep, that is what I thought. Intel kept this low key until a patch was ready.




    It's core to their stated policy.
    https://www.intel.com/content/www/us/en/corporate-responsibility/product-security-disclosure-policy.html
     
     

    i9-7900X | Asus ROG STRIX X299E | Custom loop | EVGA SuperNOVA 1600 P2 | EVGA 3090 K|NGP|N with Optimus block | 64GB Corsair Vengeance Pro 3200Mhz DDR4 | 2x Samsung 970 EVO 2TB NVME | 2x 4TB WD Black | DG-87 case | 3x LG 27" 4k |  HyperX Alloy Elite 2 kbd | HyperX Pulsefire Haste mse | HyperX Pulsefire RGB mat

     
    Heatware: https://www.heatware.com/u/96922/to
     
    #5
    Jump to: