Exploiting Lenovo's UEFI vulnerability/backdoor to flash unsigned BIOS
Posted: Wed Jul 06, 2016 2:00 pm
Dmytro Oleksiuk aka Cr4sh recently documented a privileges escalation vulnerability in Lenovo's EFI code which, among other things, can be used to remove write protection of the BIOS portion of the firmware (the EC portion is already writable, making the keyboard and battery mods possible). Cr4sh went as far as releasing a proof of concept of the vulnerability https://github.com/Cr4sh/ThinkPwn/ and people already started thinking about the possible use case of flashing a whitelist-free bios, at least on *30 generation machines https://github.com/Cr4sh/ThinkPwn/issues/2
So, what do the authors of the brilliant keyboard mod (hamish, nitrocaster, I am looking at you
) think about all this?
DDDDD
So, what do the authors of the brilliant keyboard mod (hamish, nitrocaster, I am looking at you