Database/Firmware, BMC & network fabric
MSI / Intel Boot Guard OEM key leak: The Money Message ransomware dump exposed MSI's firmware image-signing private
Impact
The Money Message ransomware dump exposed MSI's firmware image-signing private keys for 57 products and Intel Boot Guard KM/BPM private keys for 116 products, reportedly touching Intel, Lenovo and Supermicro platforms. An attacker can sign a firmware image that the hardware root of trust accepts — Boot Guard is effectively void on affected silicon and the implant survives any OS reinstall
Who can reach it
Supply chain / local flash
What to do
There is no patch. Boot Guard keys are fused into the CPU at manufacture, so revocation is impossible on shipped hardware. The only response is to treat Boot Guard as non-authoritative on affected platforms and add an independent firmware-measurement/attestation layer
References
Related entries
- Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance isNCVD-2024-001-intel-sgx-cache-side-channel-on · Intel SGX (cache side channel on sub-cacheline access)Unscored
- Platform attestation as an operational control (fTPM vs discrete TPM trust): Design-level: on most GPU servers the TPMNCVD-2024-001-platform-attestation-as-an-opera · Platform attestation as an operational control (fTPM vs discrete TPM trust)Unscored
- Intel processors (Indirect Branch Predictor structure): Indirector: reverse-engineering the Indirect Branch PredictorNCVD-2024-002-intel-processors-indirect-branch · Intel processors (Indirect Branch Predictor structure)Unscored
- Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance isNCVD-2024-006-intel-sgx-cache-side-channel-on · Intel SGX (cache side channel on sub-cacheline access)Unscored
- Intel processors (Indirect Branch Predictor structure): Indirector: reverse-engineering the Indirect Branch PredictorNCVD-2024-007-intel-processors-indirect-branch · Intel processors (Indirect Branch Predictor structure)Unscored
- ASPEED AST2600 / AST2700 hardware root of trust in OpenBMC builds: AST2600 has a fuse-backed secure boot that verifiesNCVD-2025-001-aspeed-ast2600-ast2700-hardware · ASPEED AST2600 / AST2700 hardware root of trust in OpenBMC buildsUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.