Transcription of UEFI Firmware - Securing SMM
{{id}} {{{paragraph}}}
Presented by uefi Firmware Securing SMM. uefi Spring Plugfest May 18-22, 2015. Presented by Dick Wilkins, Principal Technology Liaison Updated 2011-06-01. uefi Plugfest May 2015 1. Agenda Introduction SMM Attack Vectors Mitigation Strategies NX Protection in SMM. Closing Remarks uefi Plugfest May 2015 2. SMM is Under Attack uefi Plugfest May 2015 3. Introduction Why are we talking about this? We believe these vulnerabilities are widespread Some implementers may not be aware of their vulnerabilities We want to share our best practices in an effort to raise the level of security across the industry uefi Plugfest May 2015 4. SMM Attack Vectors uefi Plugfest May 2015 5. SMM Attack Vectors Corruption of SMRAM Contents Pass in a buffer ptr just below SMRAM and request a write SMRAM. into the buffer Pass in a buffer ptr and buffer ptr size, then quickly increase the size to extend into SMRAM. If BIOS reads size twice, you ptr might win the race Modify a ptr located outside of SMRAM that is used in an SMI.
presented by UEFI Firmware –Securing SMM UEFI Spring Plugfest –May 18-22, 2015 Presented by Dick Wilkins, Ph.D. Principal Technology Liaison UEFI Plugfest –May 2015 www.uefi.org 1
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}