Advertisement
Promo

Security threats Toolkit

Intel motherboards suffer Bios flaws

Tom Espiner ZDNet.co.uk

Published: 29 Jul 2009 15:29 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Intel has warned that a number of its desktop and server motherboards have Basic Input Output Software (Bios) security issues.

The chip company released Bios updates on Wednesday, and wrote in an in an advisory that certain models of its motherboards have privilege escalation flaws.

The vulnerabilities could allow an attacker who has gained administrative privileges to change code running in system-management mode, a privileged environment that runs outside of operating system control.

"Malicious software running in this environment could therefore perform any number of operations," Intel said in its advisory.

The hardware maker said it was not aware of the flaws being exploited, but recommended that administrators apply the Bios updates.

The affected desktop motherboards are: D5400XS, DX58SO, DX48BT2, DX38BT, DP45SG, DQ45CB, DQ45EK, DQ43AP, DB43LD, DG41MJ, DG41RQ, DG41TY, DG45ID, DG45FC, DG43NB, DP43TF, DQ35JO, DQ35MP, DG33BU, DG33FB, DG33TL, DP35DP, D945GSEJT, D945GCLF and D945GCLF2.

The affected server boards are the S3000, S3200, S5000, S5400 and S5500 series.

The flaw was uncovered by Alexander Tereshkin, Rafal Wojtczuk and Joanna Rutkowska, researchers from Invisible Things Lab. Last year, Rutkovska presented a high-privilege rootkit problem in Xen hypervisor which led to Intel putting out a Bios update.

In addition, Intel's first 34nm SSD was hit by a Bios flaw shortly after being released last week.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
12 out of 12 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters