LogoFAIL
CVE identifierCVE-2023-40238
DiscovererBinarly
Affected hardwareMotherboard firmware with TianoCore EDK II, including Insyde InsydeH2O, AMI Aptio, and Phoenix SCT firmware

LogoFAIL is a security vulnerability and exploit thereof that affects computer motherboard firmware with TianoCore EDK II, including Insyde Software's InsydeH2O modules and similar code in AMI and Phoenix firmware, which are commonly found on both Intel and AMD motherboards, and which enable loading of custom boot logos. The exploit was discovered in December 2023 by researchers at Binarly.[1][2]

Description

edit

The vulnerability exists when the Driver Execution Environment (DXE) is active after a successful Power On Self Test (POST) in the UEFI firmware (also known as the BIOS). The UEFI's boot logo is replaced with the exploit payload at this point, and the exploit can then take control of the system.[2]

Patches

edit

Intel patched the issue in Intel Management Engine (ME) version 16.1.30.2307 in December 2023. AMD addressed the problem in AGESA version 1.2.0.b, although some motherboard manufacturers did not include the fix under AGESA 1.2.0.c.[3]

edit

References

edit


📚 Artikel Terkait di Wikipedia

BootKitty

replacements. BootKitty primarily uses the exploit LogoFAIL in order to gain firmware-level persistence. Using LogoFAIL, BootKitty embed shellcode into two BMP image

Insyde Software

vulnerabilities discovered on a number of UEFI implementations which they termed "LogoFAIL", including Insyde's. The firm highlighted that malicious actors can bypass

TianoCore EDK II

moved into a "stable tag" format. In December 2023 a vulnerability termed "LogoFAIL" was discovered associated with EDK II which enabled an attacker to insert

AGESA

vulnerabilities (AMD-SB-4008) January 2024 1.1.0.1 Fixed security vulnerabilities (LogoFAIL) January 2024 1.1.0.0 Bugfixes December 2023 1.0.9.0 Bugfixes concerning

Scattered Lapsus$ Hunters

Log4Shell (2021) Account pre-hijacking (2022) Retbleed (2022) Downfall (2023) LogoFAIL (2023) Reptar (2023) Terrapin (2023) GoFetch (2024) Sinkclose (2024) Copy

Fur Affinity

Log4Shell (2021) Account pre-hijacking (2022) Retbleed (2022) Downfall (2023) LogoFAIL (2023) Reptar (2023) Terrapin (2023) GoFetch (2024) Sinkclose (2024) Copy

Emotet

Log4Shell (2021) Account pre-hijacking (2022) Retbleed (2022) Downfall (2023) LogoFAIL (2023) Reptar (2023) Terrapin (2023) GoFetch (2024) Sinkclose (2024) Copy

Timeline of computing 2020–present

Log4Shell (2021) Account pre-hijacking (2022) Retbleed (2022) Downfall (2023) LogoFAIL (2023) Reptar (2023) Terrapin (2023) GoFetch (2024) Sinkclose (2024) Copy