PKfail Flaw Exposes Millions to UEFI Malware Attacks!

Опубликовано: 07 Сентябрь 2026
на канале: Jiffry Uthumalebbe
185
5

*Summary: PKfail Firmware Vulnerability*

Hundreds of UEFI products from 10 vendors, including Acer, Dell, HP, Intel, and Lenovo, are compromised due to a critical firmware supply-chain issue known as PKfail. This vulnerability allows attackers to bypass Secure Boot and install malware.

The issue arises from using a test Secure Boot master key (Platform Key or PK) generated by American Megatrends International (AMI), labeled "DO NOT TRUST." Many device vendors failed to replace this test key with securely generated ones, resulting in devices shipping with untrusted keys.

The Binarly Research Team discovered the issue, highlighting that the first vulnerable firmware was released in May 2012, with the latest in June 2024. Over 813 products are affected.

To mitigate PKfail, vendors should follow cryptographic key management best practices and replace test keys with securely generated ones. Users are advised to monitor and apply firmware updates promptly. Binarly provides a free tool on pk.fail to scan for vulnerable devices and malicious payloads.