Database/Firmware, BMC & network fabric

Gigabyte UEFI firmware (OEM update-dropper in firmware): Gigabyte firmware shipped a UEFI module that writes a Windows
Impact
Gigabyte firmware shipped a UEFI module that writes a Windows executable to disk at every boot and has it fetch and run further code from Gigabyte-controlled URLs - one of them plain HTTP, with weak certificate validation on the others. It is not malware, it is the vendor's own updater, but it behaves exactly like a firmware implant: an unremovable, boot-persistent downloader with no user consent and no way to disable it from the OS. Anyone who can MITM that fetch, or who compromises the vendor's distribution point, gets code execution on every affected machine at every boot.
Who can reach it
A network attacker in path of the update fetch, or a supply-chain compromise of the vendor endpoint. No access to the machine needed.
What to do
Gigabyte published firmware updates that fix the transport and validation; applying them is a per-board BIOS flash plus reboot. Where the platform allows it, disable the 'APP Center Download & Install' option in BIOS setup - a config-only mitigation you can push faster than a firmware campaign. The broader operator lesson: audit what your board vendor's firmware talks to on the network before a node ever carries tenant workload, and block outbound egress from the provisioning network by default.
References
Related entries
- Intel processors with Linear Address Masking (LAM): SLAM: Linear Address Masking, a feature intended to let softwareNCVD-2023-001-intel-processors-with-linear-add · Intel processors with Linear Address Masking (LAM)Unscored
- MSI / Intel Boot Guard OEM key leak: The Money Message ransomware dump exposed MSI's firmware image-signing privateNCVD-2023-001-msi-intel-boot-guard-oem-key-lea · MSI / Intel Boot Guard OEM key leakUnscored
- Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance isNCVD-2024-001-intel-sgx-cache-side-channel-on · Intel SGX (cache side channel on sub-cacheline access)Unscored
- Platform attestation as an operational control (fTPM vs discrete TPM trust): Design-level: on most GPU servers the TPMNCVD-2024-001-platform-attestation-as-an-opera · Platform attestation as an operational control (fTPM vs discrete TPM trust)Unscored
- Intel processors (Indirect Branch Predictor structure): Indirector: reverse-engineering the Indirect Branch PredictorNCVD-2024-002-intel-processors-indirect-branch · Intel processors (Indirect Branch Predictor structure)Unscored
- Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance isNCVD-2024-006-intel-sgx-cache-side-channel-on · Intel SGX (cache side channel on sub-cacheline access)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.