The PKfail vulnerability is a significant security issue affecting over 200 device models of Secure Boot. PKfail is a critical firmware supply-chain issue that undermines the Secure Boot process in the UEFI ecosystem.
Secure Boot ensures that only trusted software is loaded during the boot process, preventing unauthorized code execution. However, PKfail compromises this security feature by exploiting weaknesses in managing Platform Keys (PKs).
PKfail allows attackers to completely bypass Secure Boot protections, which are important for keeping the boot process safe. Attackers can potentially install persistent UEFI malware like bootkits, which can survive operating system reinstalls and are very difficult to detect and remove.
Join our free webinar to learn about combating slow DDoS attacks, a major threat today.
The Binarly Research Team found that many products use a test Platform Key created by American Megatrends International (AMI). This key was probably included in their reference implementation with the expectation that it would be replaced with another key generated safely.
The vulnerability is so widespread that it could be used to launch large-scale attacks on multiple vendors in the supply chain.
The PKfail vulnerability affects hundreds of UEFI products from multiple vendors, including Acer, Dell, Fujitsu, HP, Intel, Lenovo, and Supermicro. The issue spans over a decade, with the first vulnerable firmware released in May 2012 and the latest in June 2024. Exploiting this vulnerability allows attackers to:
To address the PKfail vulnerability, the following steps are recommended:
The PKfail vulnerability reveals significant vulnerabilities in the UEFI ecosystem’s supply chain security. By following the recommended strategies to reduce the risk of exploitation, both device vendors and users can improve their devices’ overall security.
Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…