MORE FUN WITH FIRMWARE — Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attack UEFIs booting Windows and Linux devices can be hacked by malicious logo images.
Dan Goodin – Dec 6, 2023 3:02 pm UTC EnlargeGetty Images reader comments 195
Hundreds of Windows and Linux computer models from virtually all hardware makers are vulnerable to a new attack that executes malicious firmware early in the boot-up sequence, a feat that allows infections that are nearly impossible to detect or remove using current defense mechanisms.
The attackdubbed LogoFAIL by the researchers who devised itis notable for the relative ease in carrying it out, the breadth of both consumer- and enterprise-grade models that are susceptible, and the high level of control it gains over them. In many cases, LogoFAIL can be remotely executed in post-exploit situations using techniques that cant be spotted by traditional endpoint security products. And because exploits run during the earliest stages of the boot process, they are able to bypass a host of defenses, including the industry-wide Secure Boot, Intels Secure Boot, and similar protections from other companies that are devised to prevent so-called bootkit infections. Game over for platform security
LogoFAIL is a constellation of two dozen newly discovered vulnerabilities that have lurked for years, if not decades, in Unified Extensible Firmware Interfaces responsible for booting modern devices that run Windows or Linux. The vulnerabilities are the product of almost a years worth of work by Binarly, a firm that helps customers identify and secure vulnerable firmware.
The vulnerabilities are the subject of a coordinated mass disclosure released Wednesday. The participating companies comprise nearly the entirety of the x64 and ARM CPU ecosystem, starting with UEFI suppliers AMI, Insyde, and Phoenix (sometimes still called IBVs or independent BIOS vendors); device manufacturers such as Lenovo, Dell, and HP; and the makers of the CPUs that go inside the devices, usually Intel, AMD or designers of ARM CPUs. The researchers unveiled the attack on Wednesday at the Black Hat Security Conference in London. Advertisement
The affected parties are releasing advisories that disclose which of their products are vulnerable and where to obtain security patches. Links to advisories and a list of vulnerability designations appears at the end of this article.
As its name suggests, LogoFAIL involves logos, specifically those of the hardware seller that are displayed on the device screen early in the boot process, while the UEFI is still running. Image parsers in UEFIs from all three major IBVs are riddled with roughly a dozen critical vulnerabilities that have gone unnoticed until now. By replacing the legitimate logo images with identical-looking ones that have been specially crafted to exploit these bugs, LogoFAIL makes it possible to execute malicious code at the most sensitive stage of the boot process, which is known as DXE, short for Driver Execution Environment.
Once arbitrary code execution is achieved during the DXE phase, its game over for platform security, researchers from Binarly, the security firm that discovered the vulnerabilities, wrote in a whitepaper. From this stage, we have full control over the memory and the disk of the target device, thus including the operating system that will be started.
From there, LogoFAIL can deliver a second-stage payload that drops an executable onto the hard drive before the main OS has even started. The following video demonstrates a proof-of-concept exploit created by the researchers. The infected devicea Gen 2 Lenovo ThinkCentre M70s running an 11th-Gen Intel Core with a UEFI released in Juneruns standard firmware defenses, including Secure Boot and Intel Boot Guard. LogoFAIL.
In an email, Binarly founder and CEO Alex Matrosov wrote:
LogoFAIL is a newly discovered set of high-impact security vulnerabilities affecting different image parsing libraries used in the system firmware by various vendors during the device boot process. These vulnerabilities are present in most cases inside reference code, impacting not a single vendor but the entire ecosystem across this code and device vendors where it is used. This attack can give a threat actor an advantage in bypassing most endpoint security solutions and delivering a stealth firmware bootkit that will persist in a firmware capsule with a modified logo image. Page: 1 2 3 4 Next → reader comments 195 Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars
Davina McCall’s partner has said she is out of surgery after undergoing an operation to remove a brain tumour.
The 57-year-old television presenter had revealed in a video posted on Instagram earlier today she had a benign brain tumour, a colloid cyst, which she described as “very rare”.
She said the chances of having it were “three in a million,” and she had discovered it a few months ago, after a company offered her a health scan in return for giving a menopause talk.
She also announced she would be having the surgery this evening.
Now her partner – hairdresser Michael Douglas – has posted on social media to say the operation went well.
He said: “Hey all. Davina is out of surgery and according to the surgeon it was textbook! She’s currently recovering in ICU as a precaution, as you can imagine she’s utterly exhausted.
“Thanks so much for all the love from everyone on here… it’s powerful stuff, we are super grateful.”
McCall earlier said the tumour’s discovery came as a shock.
She said: “I slightly put my head in the sand for a while, and then I saw quite a few neurosurgeons, I got lots of opinions. I realised that I have to get it taken out.”
Advertisement
McCall described it as “big”, 14mm wide, adding: “It needs to come out, because if it grows it would be bad.”
She explained that she would have it removed via a craniotomy, describing the procedure: “They go through the top of my head here and through the two halves of my brain to the middle.
“They get the cyst, take it out, empty it, and Bob’s your uncle.”
She added before the surgery: “Say a prayer for me, I am in good spirits.”
She said she would be in hospital “for around nine days”, but during her recovery, she would be “off my phone for a while”.
Joking and smiling, she urged fans “not to worry about me”, admitting, “I’m doing that enough!”
She went on to counter that, explaining: “I’m not worrying too much, and I am in a good space, and I have all the faith in the world in my surgeon and his team, and I’m handing the reins over to him. He knows what he’s doing, and I’m going to do the getting better bit after.”
She signed off saying, “see you on the other side”.
What is a benign brain tumour?
According to the NHS website, a benign (non-cancerous) brain tumour is a mass of cells that grows relatively slowly in the brain.
They are unlikely to spread, but are still serious and can be life-threatening.
When successfully removed, a tumour will not usually return at all, but if it cannot be completely removed it may grow back, and so will be monitored using scans or treated with radiotherapy.
Many people return to normal activities following successful surgery, but some are left with persistent problems, such as seizures and difficulties with speech and walking.
Non-cancerous brain tumours are more common in people over the age of 50, and symptoms include headaches, blackouts, behavioural changes and loss of consciousness.
Davina McCall says her tumour is a colloid cyst – which is made up of a gelatinous material. Symptoms can include headache, vertigo, memory deficits, diplopia, behavioural disturbances, and in extreme cases, sudden death.
Celebrity friends were quick to send their support, with stars including Rylan, Alan Carr and Holly Willoughby sending love.
According to the NHS, non-cancerous brain tumours are slow-growing and unlikely to spread, but are still serious and can be life-threatening.
McCall rose to fame presenting on MTV in the mid-1990s, and later on Channel 4’s Streetmate, before becoming a household name as the host of Big Brother from 2000 to 2010.
She’s gone on to present programmes across the networks, and currently presents ITV dating show My Mum, Your Dad.
Last year, McCall was appointed Member of the Order of the British Empire (MBE) in the 2023 Birthday Honours for services to broadcasting.
In recent years, McCall has spoken regularly on women’s health and the effects of menopause in a bid to break taboos around the subject. Her 2022 book, Menopausing, won book of the year at the British Book Awards.
The same year, McCall fronted the Channel 4 documentary Davina McCall: Sex, Mind And The Menopause, and told the BBC that the perimenopausal symptoms caused her difficulties multi-tasking and she considered that she had a brain tumour or Alzheimer’s disease at the time.
The presenter has previously raised money for Cancer Research UK by running for Race For Life in honour of her late sister, Caroline Baday, who died from lung cancer in 2012 at the age of 50.
Married twice, McCall has three children, two daughters and a son, with her second husband, presenter Matthew Robertson.
She has lived with Douglas since 2022, and they present a weekly lifestyle podcast together, Making The Cut.
McCall explained it “needed to come out, because if it grows it would be bad,” and described a procedure called a craniotomy which would remove the cyst through the top of her head.
The former Big Brother host said she was “in good spirits,” and would be in hospital “for around nine days” following the procedure.
Please use Chrome browser for a more accessible video player
2:49
Davina McCall diagnosed with rare brain tumour.
It’s not clear on which day McCall’s surgery is scheduled, or if she has had the procedure yet.
Quick to share his love with the 57-year-old star, presenter Rylan wrote: “We’re all thinking of you beautiful,” while comedian Alan Carr wrote: “Big love my darling!!”
Ex-This Morning presenter Holly Willoughby wrote: “I’m sending you all the love and then a whole lot more,” and singer Ashley Roberts added: “All the love gorgeous one!! Sending all the healing vibes. Love you!!”
Former Popstars judge and presenter Nicki Chapman wrote: “You and I have chatted about this day… you are in amazing hands with your surgeon and the team. Everyone loves you.
Advertisement
“Thank you for not only being a brave girl but for sharing your condition. You will help sooooo many other people. big hugs. 30-second rule. See you soon N xx.”
Actress and chef Lisa Faulkner wrote: “Sending all my love to you. Best wishes and all positive prayers for a speedy recovery”.
McCall’s current partner, hairdresser Michael Douglas, has said he will be sharing updates from her account while she is “off-grid” and recovering, assuring fans the presenter is “in great shape and in very good hands”.
Other celebrities to share positive thoughts included Stacey Dooley, Donna Air, Helen Skelton, Denise Van Outen and Kimberly Wyatt.
McCall rose to fame presenting on MTV in the mid-1990s, and later on Channel 4’s Streetmate, before becoming a household name as the host of Big Brother from 2000 to 2010.
Follow Sky News on WhatsApp
Keep up with all the latest news from the UK and around the world by following Sky News
She’s gone on to present programmes across the networks, and last year was appointed Member of the Order of the British Empire (MBE) in the 2023 Birthday Honours for services to broadcasting.
She has three children with her second husband, presenter Matthew Robertson.
Conan O’Brien has been announced as the host of next year’s Oscars.
It’s the Emmy Award-winning comedian’s first time heading up the ceremony, which is Hollywood‘s most high-profile showbiz event.
“America demanded it and now it’s happening: Taco Bell’s new Cheesy Chalupa Supreme. In other news, I’m hosting the Oscars,” O’Brien said in a statement.
He also shared a spoof short video on social media, showing him clasping an Oscar statuette and thanking the Academy for his Oscar, before clarifying he was hosting the show rather than receiving an award.
The 61-year-old TV presenter, writer, producer and comedian is best known for hosting the late-night talk shows Late Night with Conan O’Brien, The Tonight Show with Conan O’Brien and Conan.
X
This content is provided by X, which may be using cookies and other technologies.
To show you this content, we need your permission to use cookies.
You can use the buttons below to amend your preferences to enable X cookies or to allow those cookies just once.
You can change your settings at any time via the Privacy Options.
Unfortunately we have been unable to verify if you have consented to X cookies.
To view this content you can use the button below to allow X cookies for this session only.
Before fronting his own self-named shows, he wrote for the enormously popular US late-night sketch show Saturday Night Live and the long-running satirical cartoon The Simpsons.
Between 2019 and 2021 the Oscars went without a main presenter.
Oscars executive producers Raj Kapoor and Katy Mullan said in a statement: “Conan has all the qualities of a great Oscars host, he is incredibly witty, charismatic and funny and has proven himself to be a master of live event television.
“We are so looking forward to working with him to deliver a fresh, exciting and celebratory show for Hollywood’s biggest night.”
Follow Sky News on WhatsApp
Keep up with all the latest news from the UK and around the world by following Sky News