Hundreds of Consumer and Enterprise Devices Vulnerable to LogoFAIL

Dec 13, 2023

LogoFAIL is a collection of vulnerabilities that have been around for years and attack both Linux and Windows

At Black Hat Europe 2023, Fabio Pagani shared a presentation about a newly discovered collection of vulnerabilities being used against Linux and Windows systems that involves, believe it or not, logos.

LogoFAIL is a group of vulnerabilities that targets UEFI code from various firmware/BIOS vendors through high-impact flaws in the image parsing libraries within the firmware.

According to Binarly, "One of the most important discoveries is that LogoFAIL is not silicon-specific and can impact x86 and ARM-based devices. LogoFAIL is UEFI and IBV-specific because of the specifics of vulnerable image parsers that have been used. That shows a much broader impact from the perspective of the discoveries that will be presented on Dec 6th."

The vulnerability was originally discovered on Lenovo devices with Insyde, AMI, and Phoenix reference code and was reported under the advisory BRLY-2023-006.

After the research group was able to demonstrate a number of attack surfaces from image-parsing firmware components, it became a "massive industry-wide disclosure."

LogoFAIL allows attackers to store malicious images on either the EFI System Partition or inside unsigned sections of firmware updates. When the images are parsed at boot, the vulnerability is triggered and the payload can then be executed to hijack the process and bypass security features.

Hundreds of consumer and enterprise devices (from numerous vendors) are vulnerable. As of now, there's no indication of when this vulnerability will be patched.
 
 
 

 
 
 

Related content

  • News

    In the news: Hundreds of Consumer and Enterprise Devices Vulnerable to LogoFAIL; Linux Mint 21.3 Beta Available with Latest Version of Cinnamon; Arch Linux 2023.12.01 Released with a Much-Improved Installer; Zorin OS 17 Beta Available for Testing; Red Hat Migrates RHEL from Xorg to Wayland; PipeWire 1.0 Officially Released; Rocky Linux 9.3 Available for Download; Ubuntu Budgie Shifts How to Tackle Wayland; and TUXEDO's New Ultraportable Linux Workstation Released.

  • Huge Hole in Yoggie USB Stick Firewall

    A full-fledged Linux computer on a USB stick: Yoggie uses this astonishing hardware trick to protect Windows machines against Web-based attacks. But there are some things that do not work as intended by the developers as an exhaustive test in Linux Magazine #94 / September will reveal. Just a few simple tricks were all it took to work around the firewall.

comments powered by Disqus
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters

Support Our Work

Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.

Learn More

News