No need to stress; assess the situation and act accordingly.
No need to stress; assess the situation and act accordingly.
It raises moderate concern. In theory, a userland program could run if elevated permissions are granted. If malicious software appears and you approve admin access, it might compromise the system. Without admin rights, code changes in UEFI should be blocked. I’m unsure if Windows has a workaround for this restriction, but a simple browser visit shouldn’t bypass it. A breach could leave your board vulnerable, as BIOS updates won’t always resolve the issue. If connected to the internet, an attacker could take control. You might safely use it offline—like a retro gaming setup or HTPC—but don’t rely on it for critical tasks. Avoid connecting it to your network and keep it isolated.
If your board vendor hasn’t issued a patch yet, don’t worry. Many of these low-level exploits are difficult unless you have direct access to your system. Make sure your operating system and other programs are current, and monitor for any future BIOS updates from the manufacturer.
It probably would still be fine, but it could end badly. What concerns me is that it's theoretically possible to do this without in-person access to the computer. It's a way bigger threat to users than similarly bad vulnerabilities in the past that required physical access to the hardware. I guess in the grand scheme of things, the risk is still low. In a sense, nothing changes, as you should never be giving admin permissions to untrusted software regardless of whether this specific vulnerability exists.