Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability
BID:67947
Info
Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability
| Bugtraq ID: | 67947 |
| Class: | Design Error |
| CVE: |
CVE-2014-2961 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 09 2014 12:00AM |
| Updated: | Jun 09 2014 12:00AM |
| Credit: | Corey Kallenberg, Xeno Kovah, John Butterworth, and Sam Cornwell of MITRE Corporation |
| Vulnerable: |
Intel Server System R1000SP Family 0 Intel Server System R1000RP Family 0 Intel Server System R1000JP Family 0 Intel Server System R1000GZ Family 0 Intel Server System R1000GL Family 0 Intel Server System R1000EP Family 0 Intel Server System R1000BB Family 0 Intel Server System P4304BT 0 Intel Server System P4000SC Family 0 Intel Server System P4000RP Family 0 Intel Server System P4000IP Family 0 Intel Server System P4000CP Family 0 Intel Server System H2000WP Family 0 Intel Server System H2000LP Family 0 Intel Server System H2000JF Family 0 Intel Server Board S5520UR 0 Intel Server Board S5520HCT 0 Intel Server Board S5520HC 0 Intel Server Board S5500WB 0 Intel Server Board S5500HCV 0 Intel Server Board S5500BC 0 Intel Server Board S4600LT Family 0 Intel Server Board S4600LH Family 0 Intel Server Board S3420GP 0 Intel Server Board S2600WP 0 Intel Server Board S2600JF 0 Intel Server Board S2600IP Family 0 Intel Server Board S2600GZ 0 Intel Server Board S2600GL 0 Intel Server Board S2600CP Family 0 Intel Server Board S2600CO Family 0 Intel Server Board S2400SC Family 0 Intel Server Board S2400LP Family 0 Intel Server Board S2400GP Family 0 Intel Server Board S2400EP Family 0 Intel Server Board S2400BB 0 Intel Server Board S1600JP Family 0 Intel Server Board S1400SP Family 0 Intel Server Board S1400FP Family 0 Intel Server Board S1200RP 0 Intel Server Board S1200KP 0 Intel Server Board S1200BT 0 Intel Quark SoC X1000 Transportation Reference Design 1.0.1 Intel Quark SoC X1000 Industrial/Energy Reference Design 1.0.1 Intel NUC with Intel Core i5 processor (D54250WYKH) 0 Intel NUC with Intel Core i5 processor (D54250WYK) 0 Intel NUC with Intel Core i3 processor (D34010WYKH) 0 Intel NUC with Intel Core i3 processor (D34010WYK) 0 Intel NUC with Intel Core i5 processor (D53427RKE, D53427HYE) 0 Intel NUC with Intel Celeron Processor (DN2820FYKH) 0 Intel NUC with Intel Atom Processor (DE3815TYKHE) 0 Intel Galileo board Generation 2 (pre-release) 1.0.1 Intel Galileo board 1.0.1 |
| Not Vulnerable: | |
Discussion
Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability
Multiple products that implement UEFI secure boot are prone to a local security-bypass vulnerability.
Attackers with physical access to the computer running the vulnerable firmware can exploit this issue to bypass certain security restrictions and trigger denial-of-service conditions.
NOTE: Very limited information is currently available regarding this issue. We will update this BID as more information emerges.
Multiple products that implement UEFI secure boot are prone to a local security-bypass vulnerability.
Attackers with physical access to the computer running the vulnerable firmware can exploit this issue to bypass certain security restrictions and trigger denial-of-service conditions.
NOTE: Very limited information is currently available regarding this issue. We will update this BID as more information emerges.
Exploit / POC
Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability
An attacker with physical access to the computer can exploit this issue.
The researcher who discovered this issue has created a functional exploit. The exploit is otherwise not publicly available. Please see the references for more information.
An attacker with physical access to the computer can exploit this issue.
The researcher who discovered this issue has created a functional exploit. The exploit is otherwise not publicly available. Please see the references for more information.
Solution / Fix
Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability
References:
References: