• News/
  • https://www.bleepingcomputer.com/news/security/gigabyte-motherboards-vulnerable-to-uefi-malware-bypassing-secure-boot/

Gigabyte motherboards vulnerable to UEFI malware bypassing Secure Boot

BleepingComputer
·
Bill Toulas
·
Published Jul 14, 2025
·
Updated

Dozens of Gigabyte motherboard models run on UEFI firmware vulnerable to security issues that allow planting bootkit malware that is invisible to the operating system and can survive reinstalls. The vulnerabilities could allow attackers with local or remote admin permissions to execute arbitrary code in System Management Mode (SMM), an environment isolated from the operating system (OS) and with more privileges on the machine. Mechanisms running code below the OS have low-level hardware access and initiate at boot time. Because of this, malware in these environments can bypass traditional security defenses on the system. UEFI, or Unified Extensible Firmware Interface, firmware is more secure due to the Secure Boot feature that ensures through cryptographic verifications that a device uses at boot time code that is safe and trusted. For this reason, UEFI-level malware like bootkits (BlackLotus, CosmicStrand, MosaicAggressor, MoonBounce, LoJax) can deploy malicious code at every boot. The four vulnerabilities are in Gigabyte firmware implementations and were discovered by researchers at firmware security company Binarly, who shared their findings with Carnegie Mellon University’s CERT Coordination Center (CERT/CC). The original firmware supplier is American Megatrends Inc. (AMI), which addressed the issues after a private disclosure but some OEM firmware builds (e.g. Gigabyte's) did not implement the fixes at the time. In Gigabyte firmware implementations, Binarly found the fo...

Read full article

Affected Software

1 affected component
GIGABYTE motherboard
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses vulnerabilities in Gigabyte motherboards that can be exploited by UEFI malware to bypass Secure Boot.

2

What security implications are discussed?

The vulnerabilities allow for the implantation of bootkit malware that can evade detection and persist even after system reinstalls.

3

What products or hardware are affected?

Dozens of Gigabyte motherboard models that utilize UEFI firmware are affected by these security vulnerabilities.

4

How can the vulnerabilities impact users?

Users may face potential system compromise as the vulnerabilities allow malware to operate undetected at the boot level.

5

What is UEFI and why is it important in this context?

UEFI is a firmware interface that initializes hardware during the boot process, and its vulnerabilities can lead to severe security risks if exploited.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203