logo

New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock

ID: b63a2e64-de70-5831-b697-3cf5a93e4138

STIX ID: report--b63a2e64-de70-5831-b697-3cf5a93e4138

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2025-12-19

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Researchers disclosed UEFI firmware flaws in select ASUS, Gigabyte, MSI, and ASRock motherboards that can falsely report DMA protections as enabled while failing to initialize the IOMMU, enabling physical pre-boot DMA attacks via malicious PCIe devices. The issue (multiple CVEs) can allow reading or modifying RAM before the OS loads, prompted vendor advisories and firmware updates, and has caused Riot Games' Vanguard anti-cheat to block affected systems from launching Valorant until mitigations are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.