MSI Board Owners: Check Your UEFI Secure Boot Settings!

plat

Level 29
Thread author
Top Poster
Sep 13, 2018
1,793
Potocki claims that MSI's firmware update version' 7C02v3C,' released on January 18, 2022, changed a default Secure Boot setting on MSI motherboards so that the system will boot even if it detects security violations.

"I decided to setup Secure Boot on my new desktop with the help of sbctl. Unfortunately, I have found that my firmware was accepting every OS image I gave it, no matter if it was trusted or not," explains the researcher in his writeup.

"As I have later discovered on 2022-12-16, it wasn't just broken firmware; MSI had changed their Secure Boot defaults to allow booting on security violations(!!)."

Potocki explains that users should set the Execution Policy to "Deny Execute" for "Removable Media" and "Fixed Media," which should only allow signed software to boot.

A complete list of the over 290 motherboards affected by this insecure setting is available on GitHub.

Personal note: Windows users w/certain MSI boards who can't update to 11 might be esp. interested. According to the Bleeping article, MSI has not yet responded with an answer on how it plans to address this issue.
 

plat

Level 29
Thread author
Top Poster
Sep 13, 2018
1,793
Dissapointed but software has always been MSI's downfall

Interesting. Very recently, the developer of MSI Afterburner (for those who don't know, it's a gpu tuning software) claimed that program was "semi-abandoned" and may be "reaching end-of-life." The reason? MSI has been unable (they claim) to forward his payments due to the Ukraine invasion.

They say they're currently "looking into it." But I cannot blame the dev--he wants his pay just like anybody. But after this revelation, it's prob. no coincidence AFB was on the list for malicious hijacking (like OBS and some others).

Wow. 🤔
 

upnorth

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 27, 2015
5,459
MSI will be rolling out new BIOS files for motherboards with ”Deny Execute” as the default setting for higher security levels.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top