F5F Stay Refreshed Hardware Desktop No need to stress; assess the situation and act accordingly.

No need to stress; assess the situation and act accordingly.

No need to stress; assess the situation and act accordingly.

L
l2p_Robinhudi
Member
67
11-27-2018, 10:06 PM
#1
They don't have any updates available to fix it.
L
l2p_Robinhudi
11-27-2018, 10:06 PM #1

They don't have any updates available to fix it.

S
Soldier_Games
Member
60
11-27-2018, 10:06 PM
#2
It raises moderate concern. In theory, a userland program could run if elevated permissions are granted. If malicious software appears and you approve admin access, it might compromise the system. Without admin rights, code changes in UEFI should be blocked. I’m unsure if Windows has a workaround for this restriction, but a simple browser visit shouldn’t bypass it. A breach could leave your board vulnerable, as BIOS updates won’t always resolve the issue. If connected to the internet, an attacker could take control. You might safely use it offline—like a retro gaming setup or HTPC—but don’t rely on it for critical tasks. Avoid connecting it to your network and keep it isolated.
S
Soldier_Games
11-27-2018, 10:06 PM #2

It raises moderate concern. In theory, a userland program could run if elevated permissions are granted. If malicious software appears and you approve admin access, it might compromise the system. Without admin rights, code changes in UEFI should be blocked. I’m unsure if Windows has a workaround for this restriction, but a simple browser visit shouldn’t bypass it. A breach could leave your board vulnerable, as BIOS updates won’t always resolve the issue. If connected to the internet, an attacker could take control. You might safely use it offline—like a retro gaming setup or HTPC—but don’t rely on it for critical tasks. Avoid connecting it to your network and keep it isolated.

X
xFqtal_
Senior Member
670
11-27-2018, 10:06 PM
#3
I don't want to watch that video, but based on the links shared, it could relate to a Gigabyte Intel SMMRAM module used in their boards. If your signature mentions the board, it shouldn't affect your situation.
X
xFqtal_
11-27-2018, 10:06 PM #3

I don't want to watch that video, but based on the links shared, it could relate to a Gigabyte Intel SMMRAM module used in their boards. If your signature mentions the board, it shouldn't affect your situation.

B
Bowling_Beast
Member
200
11-27-2018, 10:06 PM
#4
If your board vendor hasn’t issued a patch yet, don’t worry. Many of these low-level exploits are difficult unless you have direct access to your system. Make sure your operating system and other programs are current, and monitor for any future BIOS updates from the manufacturer.
B
Bowling_Beast
11-27-2018, 10:06 PM #4

If your board vendor hasn’t issued a patch yet, don’t worry. Many of these low-level exploits are difficult unless you have direct access to your system. Make sure your operating system and other programs are current, and monitor for any future BIOS updates from the manufacturer.

M
MineaBeef
Junior Member
34
11-27-2018, 10:06 PM
#5
I see only a handful of situations where things might go wrong. This appears to be a very low-risk option for regular users.
M
MineaBeef
11-27-2018, 10:06 PM #5

I see only a handful of situations where things might go wrong. This appears to be a very low-risk option for regular users.

D
dragonascape
Junior Member
3
11-27-2018, 10:06 PM
#6
It probably would still be fine, but it could end badly. What concerns me is that it's theoretically possible to do this without in-person access to the computer. It's a way bigger threat to users than similarly bad vulnerabilities in the past that required physical access to the hardware. I guess in the grand scheme of things, the risk is still low. In a sense, nothing changes, as you should never be giving admin permissions to untrusted software regardless of whether this specific vulnerability exists.
D
dragonascape
11-27-2018, 10:06 PM #6

It probably would still be fine, but it could end badly. What concerns me is that it's theoretically possible to do this without in-person access to the computer. It's a way bigger threat to users than similarly bad vulnerabilities in the past that required physical access to the hardware. I guess in the grand scheme of things, the risk is still low. In a sense, nothing changes, as you should never be giving admin permissions to untrusted software regardless of whether this specific vulnerability exists.

M
MonochromeLG
Member
74
11-27-2018, 10:06 PM
#7
Thanks.
M
MonochromeLG
11-27-2018, 10:06 PM #7

Thanks.