Cybersecurity consultants simply discovered a flaw in the UEFI firmware that many fashionable motherboards use. The “bug” may let attackers do direct reminiscence entry (DMA) assaults on programs, which can allow unauthorized customers to achieve deep and protracted entry to affected programs underneath sure situations, and the worst half is that it impacts boards from a number of main producers, together with Gigabyte, MSI, ASUS, and ASRock.
To provide you context, the PC motherboard incorporates low-level software program referred to as UEFI, or Unified Extensible Firmware Interface, which securely begins the working system and initializes {hardware} elements. One in every of its main safety obligations is to allow the Enter-Output Reminiscence Administration Unit (IOMMU), a hardware-based isolation mechanism that’s meant to safeguard system reminiscence. If arrange appropriately, the IOMMU stops exterior units from studying or writing to random components of system RAM.
Elements reminiscent of PCIe enlargement playing cards, Thunderbolt peripherals, GPUs, and comparable {hardware} that may entry reminiscence straight with out passing via the CPU are included in DMA-capable units. Malicious or compromised {hardware} can have much less of an impression as a result of these units are restricted to explicit reminiscence areas if the IOMMU is operational and correctly initialized.
The lately found vulnerability is brought on by the flawed manner this safety was arrange; in affected motherboards, the UEFI firmware says that DMA safety is on, although the IOMMU was by no means absolutely or appropriately arrange, after which the working system consequently assumes that reminiscence protections are carried out, although they aren’t actively enforced.
The problem is being tracked underneath a number of vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard distributors implement UEFI options in another way.
Researchers at Riot Video games, the developer of well-known multiplayer video games like League of Legends and Valorant, had been the primary ones to establish the vulnerability. Vanguard, Riot’s anti-cheat system, is carried out on the kernel degree and incorporates safeguards which might be meant to stop unauthorized system manipulation. Valorant could also be prevented from launching on programs which might be affected by this particular flaw, as it detects an unsafe {hardware} safety state.
There may be an necessary limitation to consider, although the doable impact could possibly be horrible: the power to bodily entry the system and join a malicious PCIe or comparable system earlier than the working system boots up are stipulations for a DMA assault. Consequently, the likelihood of widespread exploitation is considerably diminished, significantly for residential customers.
Customers are being suggested to monitor updates from their motherboard producers and apply any accessible firmware patches. Updating the UEFI firmware continues to be important to preserving system safety, significantly in mild of the continued evolution of hardware-level assaults.
Filed in . Learn extra about Asus, Cybersecurity, Gigabyte, Msi and Security.
Trending Merchandise
Wi-fi Keyboard and Mouse Combo R...
ASUS TUF Gaming 24” (23.8” view...
ASUS TUF Gaming 27″ 1080P Mon...
CHONCHOW LED Keyboard and Mouse, 10...
SAMSUNG 34″ ViewFinity S50GC ...
Acer Nitro 31.5″ FHD 1920 x 1...
HP 15.6″ Touchscreen Laptop c...
