Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

For Science! - Using an Unimpressive Bug in EDK II to Do Some Fun Exploitation

Summary

Turning a limited write primitive in EDK II's Tcg2Smm module into SMM code execution — the flaw only lives before the end of the DXE phase, so it chains into pre-boot privilege escalation.
Published
Collected

original ↗

Related coverage

back