BIOS Disconnect: New High-Severity Bugs Affect 128 Dell PC and Tablet Models

From thehackernews.com

Cybersecurity researchers on Thursday disclosed a chain of vulnerabilities affecting the BIOSConnect feature within Dell Client BIOS that could be abused by a privileged network adversary to gain arbitrary code execution at the BIOS/UEFI level of the affected device.

“As the attacker has the ability to remotely execute code in the pre-boot environment, this can be used to subvert the operating system and undermine fundamental trust in the device,” researchers from enterprise device security firm Eclypsium said. “The virtually unlimited control over a device that this attack can provide makes the fruit of the labor well worth it for the attacker.”

Read more…