home.social

#pixiefail — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pixiefail, aggregated by home.social.

fetched live
  1. RT @quarkslab
    Is remote code execution in UEFI firmware possible?
    Yes it is.
    Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers.
    Full details by @fdfalcon and @4Dgifts in our new blog post: blog.quarkslab.com/pixiefail-n

  2. CW: Long thread/27

    That badware is running in "Ring -1" - a zone of privilege that overrides the operating system itself.

    Here's the bad news: UEFI malware has already been detected in the wild:

    securelist.com/cosmicstrand-ue

    And here's the worst news: researchers have just identified *another* exploitable UEFI bug, dubbed #Pixiefail:

    blog.quarkslab.com/pixiefail-n

    27/

  3. New UEFI vulnerabilities send firmware devs across an entire ecosystem scrambling - Enlarge (credit: Nadezhda Kozhedub)

    UEFI firmware from five of... - arstechnica.com/?p=1996543 #vulnerabilities #pixiefail #security #exploits #biz#uefi

  4. #PixieFAIL : Nine vulnerabilities in Tianocore's EDK II IPv6 network stack. Nine vulnerabilities that affect EDK II, the de-facto open source reference implementation of the UEFI specification and possibly all implementations derived from it. - blog.quarkslab.com/pixiefail-n #security

  5. Here's the writeup on #PixieFail, 9 vulns in the UEFI reference architecture that could enable exploitation over PXE network boot using IPv6. As near as I can tell, what has been demonstrated is underflow/overflows, but no successful exploitation.

    blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html