Discover the latest trends and top-rated products — all in one place, with deals you’ll love every day!

New UEFI Firmware Flaw Exposes Popular Motherboards To Attacks

Cybersecurity experts just found a flaw in the UEFI firmware that many modern motherboards use. The “bug” could let attackers do direct memory access (DMA) attacks on systems, which may enable unauthorized users to gain deep and persistent access to affected systems under certain conditions, and the worst part is that it affects boards from several major manufacturers, including Gigabyte, MSI, ASUS, and ASRock.

To give you context, the PC motherboard contains low-level software called UEFI, or Unified Extensible Firmware Interface, which securely starts the operating system and initializes hardware components. One of its primary security obligations is to enable the Input-Output Memory Management Unit (IOMMU), a hardware-based isolation mechanism that is intended to safeguard system memory. If set up correctly, the IOMMU stops external devices from reading or writing to random parts of system RAM.

Components such as PCIe expansion cards, Thunderbolt peripherals, GPUs, and similar hardware that can access memory directly without passing through the CPU are included in DMA-capable devices. Malicious or compromised hardware can have less of an impact because these devices are limited to particular memory regions if the IOMMU is operational and properly initialized.

The recently discovered vulnerability is caused by the wrong way this protection was set up; in affected motherboards, the UEFI firmware says that DMA protection is on, even though the IOMMU was never fully or correctly set up, and then the operating system consequently assumes that memory protections are implemented, even though they are not actively enforced.

The issue is being tracked under multiple vulnerability identifiers: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, as motherboard vendors implement UEFI features differently.

Researchers at Riot Games, the developer of well-known multiplayer games like League of Legends and Valorant, were the first ones to identify the vulnerability. Vanguard, Riot’s anti-cheat system, is implemented at the kernel level and incorporates safeguards that are intended to prevent unauthorized system manipulation. Valorant may be prevented from launching on systems that are affected by this specific flaw, as it detects an unsafe hardware security state.

There is an important limitation to think about, even though the possible effect could be terrible: the ability to physically access the system and connect a malicious PCIe or similar device before the operating system boots up are prerequisites for a DMA attack. Consequently, the probability of widespread exploitation is substantially diminished, particularly for residential users.

Users are being advised to monitor updates from their motherboard manufacturers and apply any available firmware patches. Updating the UEFI firmware is still essential to preserving system security, particularly in light of the ongoing evolution of hardware-level attacks.

Filed in Computers. Read more about , , , and .

Trending Products

- 31% Lenovo New 15.6″ Laptop, Inte...
Original price was: $791.99.Current price is: $549.99.

Lenovo New 15.6″ Laptop, Inte...

0
Add to compare
- 11% Thermaltake V250 Motherboard Sync A...
Original price was: $89.99.Current price is: $79.99.

Thermaltake V250 Motherboard Sync A...

0
Add to compare
- 20% Dell Wireless Keyboard and Mouse &#...
Original price was: $24.99.Current price is: $19.99.

Dell Wireless Keyboard and Mouse &#...

0
Add to compare
- 20% Sceptre Curved 24-inch Gaming Monit...
Original price was: $99.97.Current price is: $79.97.

Sceptre Curved 24-inch Gaming Monit...

0
Add to compare
- 30% HP 27h Full HD Monitor – Diag...
Original price was: $229.99.Current price is: $159.99.

HP 27h Full HD Monitor – Diag...

0
Add to compare
- 18% Wi-fi Keyboard and Mouse Combo &#82...
Original price was: $39.99.Current price is: $32.99.

Wi-fi Keyboard and Mouse Combo R...

0
Add to compare
- 29% ASUS 27 Inch Monitor – 1080P,...
Original price was: $167.79.Current price is: $119.00.

ASUS 27 Inch Monitor – 1080P,...

0
Add to compare
- 19% Lenovo V14 Gen 3 Enterprise Laptop ...
Original price was: $739.00.Current price is: $599.00.

Lenovo V14 Gen 3 Enterprise Laptop ...

0
Add to compare
- 32% Amazon Fundamentals – 27 Inch...
Original price was: $175.19.Current price is: $119.99.

Amazon Fundamentals – 27 Inch...

0
Add to compare
- 27% Thermaltake View 270 Plus TG ARGB B...
Original price was: $109.59.Current price is: $79.99.

Thermaltake View 270 Plus TG ARGB B...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

StellarTrendVault
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart