PKfail Secure Boot bypass remains a significant risk two months later

Teilen:

Roughly nine percent of tested firmware images use non-production cryptographic keys that are publicly known or leaked in data breaches, leaving many Secure Boot devices vulnerable to UEFI bootkit malware attacks.

Known as ‘PKfail,’ and now tracked as CVE-2024-8105, the supply chain attack is caused by test Secure Boot master key (Platform Key “PK”), which computer vendors were supposed to replace with their own securely generated keys.

Even though these keys were marked as “DO NOT TRUST,” they were still used by numerous computer manufacturers, including Acer, Dell,  Fujitsu, Gigabyte, HP, Intel, Lenovo, Phoenix, and Supermicro.

The issue was discovered by Binarly in late July 2024, which warned about the use of untrusted test keys, many already leaked on GitHub and other locations, on over eight hundred consumer and enterprise device models.

PKfail could allow threat actors to bypass Secure Boot protections and plant undetectable UEFI malware on vulnerable systems, leaving users no way to defend or even discover the compromise.

PKfail impact and response

As part of their research, Binarly released a “PKfail scanner,” which vendors can use to upload their firmware images to see if they’re using a test key.

Since its release, the scanner has found 791 vulnerable firmware submissions out of 10,095, according to the latest metrics.

“Based on our data, we found PKfail and non-production keys on medical devices, desktops, laptops, gaming consoles, enterprise servers, ATMs, POS terminals, and some weird places like voting machines.” reads the new report by Binarly.

The majority of the vulnerable submissions are keys from AMI (American Megatrends Inc.), followed by Insyde (61), Phoenix (4), and one submission from Supermicro.

Firmware images scanned over time
Firmware images scanned over time
Source: Binarly

For the Insyde keys, which were generated in 2011, Binarly says that the firmware image submissions reveal they’re still used in modern devices. Previously, it was assumed that they were only to be found in legacy systems.

The community has also confirmed that PKfail impacts specialized devices from Hardkernel, Beelink, and Minisforum, so the flaw’s impact is broader than first estimated.

Binarly comments that vendor response to PKfail has generally been proactive and swift, though not everyone quickly published advisories about the security risk. Bulletins on PKfail are currently available by Dell, Fujitsu, Supermicro, Gigabyte, Intel, and Phoenix.

Several vendors have already released patches or firmware updates to remove vulnerable Platform Keys or replace them with production-ready cryptographic materials, and users can get those by updating their BIOS.

If your device is no longer supported and is unlikely to receive security updates for PKfail, it is recommended that physical access to it be limited and that it be isolated from more critical parts of the network.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:23 am, Jan. 25, 2025
Wetter-Symbol 8°C
L: 7° | H: 9°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 90 %
Druck: 1000 mb
Wind: 7 mph S
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:48 am
Sonnenuntergang: 4:36 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 9°°C 1 mm 100% 7 mph 92 % 1010 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
2° | 8°°C 1 mm 100% 16 mph 91 % 1009 mb 0 mm/h
Mo. Jan. 27 9:00 pm
Wetter-Symbol
6° | 8°°C 1 mm 100% 23 mph 92 % 983 mb 0 mm/h
Di. Jan. 28 9:00 pm
Wetter-Symbol
8° | 9°°C 1 mm 100% 20 mph 84 % 995 mb 0 mm/h
Mi. Jan. 29 9:00 pm
Wetter-Symbol
5° | 8°°C 1 mm 100% 19 mph 90 % 1000 mb 0 mm/h
Today 3:00 am
Wetter-Symbol
6° | 7°°C 0 mm 0% 4 mph 90 % 1000 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 5°°C 1 mm 100% 7 mph 92 % 1001 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
5° | 5°°C 0.59 mm 59% 6 mph 73 % 1004 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
6° | 6°°C 0.22 mm 22% 7 mph 55 % 1006 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 4 mph 56 % 1008 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 70 % 1009 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 73 % 1010 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 5 mph 71 % 1009 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€99,724.90
1.04%
Ethereum(ETH)
€3,147.23
-0.58%
XRP(XRP)
€2.96
0.39%
Fesseln(USDT)
€0.95
-0.02%
Solana(SOL)
€240.12
-0.81%
USDC(USDC)
€0.95
0.00%
Dogecoin(DOGE)
€0.332966
-0.34%
Shiba Inu(SHIB)
€0.000019
-0.87%
Pepe(PEPE)
€0.000014
-2.25%
Peanut das Eichhörnchen(PNUT)
€0.341611
3.03%
Nach oben scrollen