ISC StormCast for Monday, December 4th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 4 December 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, December 4, 2023 edition of the Sands and Stormers Stormcast. |
| 0:08.2 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.1 | Researchers from binary discovered multiple vulnerabilities in UIFI firmware that are not necessarily easy to exploit, but given how |
| 0:24.8 | ubiquitous these vulnerabilities are, are certainly a concern given that UEFI firmware |
| 0:31.3 | is often sort of your root of trust when it comes to different operating systems and computers. |
| 0:38.2 | They call the flaw logo fail because, well, it deals with the boot logo. |
| 0:43.8 | The boot logo is not necessarily something that you may consider super security sensitive |
| 0:50.2 | for such. |
| 0:51.1 | It's kind of neat that you can change the logo being displayed by your system from |
| 0:56.6 | the manufacturers given design to, well, whatever you would like it to be. But of course, |
| 1:02.2 | displaying this logo does require that the firmware is able to parse these image formats. And |
| 1:10.0 | image format parsers did have a number of vulnerabilities |
| 1:14.3 | in the past. And it's exactly what's happening here. They're using outdated libraries to |
| 1:19.7 | display JPEX and other image formats that may be used here. And as a result, the system then is exploitable because these flaws can then be used here and as a result the system then is exploitable because these flaws |
| 1:30.5 | can then be used to execute opt-rate code at the time the system boots bypassing security features |
| 1:37.4 | like secure boot what makes a dizz attack kind of special and dangerous is that it doesn't |
| 1:43.6 | actually modify any of the firmers |
| 1:47.1 | code. So any kind of code integrity checks on the firmware are not going to protect you against |
| 1:53.6 | the vulnerability as the exploit is run whenever you're booting the system. And in that sense, |
| 2:00.3 | kind of persistent as long as |
| 2:02.7 | the image remains on the system. |
| 2:07.5 | And then, well, moving from a very technical to a not very technical, probably more successful |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

