Dozens of Gigabyte motherboard models run on UEFI firmware vulnerable to security issues that allow planting bootkit malware that is invisible to the operating system and can survive reinstalls. The vulnerabilities could allow attackers with local or remote admin permissions to execute arbitrary code in System Management Mode (SMM), an environment isolated from the operating system (OS) and with more privileges on the machine. Mechanisms running code below the OS have low-level hardware access and initiate at boot time. Because of this, malware in these environments can bypass traditional security defenses on the system. UEFI, or Unified Extensible Firmware Interface, firmware is more secure due to the Secure Boot feature that ensures through cryptographic verifications that a device uses at boot time code that is safe and trusted. For this reason, UEFI-level malware like bootkits (BlackLotus, CosmicStrand, MosaicAggressor, MoonBounce, LoJax) can deploy malicious code at every boot. The four vulnerabilities are in Gigabyte firmware implementations and were discovered by researchers at firmware security company Binarly, who shared their findings with Carnegie Mellon University’s CERT Coordination Center (CERT/CC). The original firmware supplier is American Megatrends Inc. (AMI), which addressed the issues after a private disclosure but some OEM firmware builds (e.g. Gigabyte's) did not implement the fixes at the time. In Gigabyte firmware implementations, Binarly found the fo...
Gigabyte motherboards vulnerable to UEFI malware bypassing Secure Boot
BleepingComputer
·Bill Toulas
·Published Jul 14, 2025
·Updated
Affected Software
1 affected component
GIGABYTE motherboard
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses vulnerabilities in Gigabyte motherboards that can be exploited by UEFI malware to bypass Secure Boot.
2
What security implications are discussed?
The vulnerabilities allow for the implantation of bootkit malware that can evade detection and persist even after system reinstalls.
3
What products or hardware are affected?
Dozens of Gigabyte motherboard models that utilize UEFI firmware are affected by these security vulnerabilities.
4
How can the vulnerabilities impact users?
Users may face potential system compromise as the vulnerabilities allow malware to operate undetected at the boot level.
5
What is UEFI and why is it important in this context?
UEFI is a firmware interface that initializes hardware during the boot process, and its vulnerabilities can lead to severe security risks if exploited.