Motherboards from Gigabyte, MSI, ASUS, ASRock at risk from new UEFI flaw attack – here’s what we know

  • UEFI flaw leaves ASUS, Gigabyte, MSI, and ASRock motherboards exposed to DMA attacks
  • Firmware falsely reports IOMMU protection enabled, allowing malicious PCIe devices pre‑boot access
  • Riot Games discovered issue; users should apply vendor firmware updates to mitigate risk

A vulnerability in the implementation of UEFI firmware has left many popular motherboards vulnerable to direct memory access (DMA) attacks, researchers have warned, with these attacks possibly resulting in stubbornly persistent access, exposure of encryption keys and credentials, and a myriad of other problems.

Most modern computers use UEFI firmware, low-level software built into the motherboard that initializes hardware and securely starts the operating system. Among other things, the firmware is responsible for initializing and correctly enabling the Input-Output Memory Management Unit (IOMMU) isolation layer.

This hardware-enforced layer sits between system RAM and devices that can read and write directly to RAM without involving the CPU – direct memory access (DMA) devices. Those include PCIe cards, Thunderbolt devices, GPUs, etc. and similar. When it is properly initialized, a malicious device cannot read or write arbitrary memory.

False positives

The vulnerability occurs because, on affected motherboards, the UEFI firmware reports that DMA protection is enabled even though the IOMMU was never correctly initialized. In other words, the system believes the memory firewall is on when it is not enforcing any rules yet.

Since different vendors implement this feature differently, the vulnerability is tracked under different identifiers. Therefore, the bug is tracked as CVE-2025-11901, CVE-2025‑14302, CVE-2025-14303, and CVE-2025-14304 and affects some motherboards from ASUS, Gigabyte, MSI, and ASRock.

It was first discovered by researchers from Riot Games, creators of some of the world’s most popular multiplayer games, such as League of Legends, or Valorant. Riot has a tool called Vanguard, which works at kernel level and prevents cheats from being used. On vulnerable systems, Vanguard blocks Valorant from starting.

While the vulnerability does sound ominous, there is a major caveat – a PCIe device needs to be connected for a DMA attack, before the operating system starts. Still, users are advised to check with their motherboard manufacturers for firmware updates.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

We translated the Palantir manifesto for actual human beings

Palantir CEO Alex Karp is a man in charge of one of the most important and frightening companies in the world. Karp's new book,...

SpaceX cuts a deal to maybe buy Cursor for $60 billion

With an IPO looming for Elon Musk's SpaceX / xAI / X combo platter of companies, SpaceX has announced an odd arrangement to either...

YouTube is muting push notifications from channels you don’t watch

YouTube notifications can get messy fast, particularly if you’re subscribed to a lot of different channels. To address that, today the company will begin...

Cash App now supports accounts for kids 6-12

Cash App, the banking and payments app run by Block, has added support for parent-managed kids accounts. The new accounts include key benefits from...

Mozilla says it patched 271 Firefox vulnerabilities thanks to Anthropic’s Claude Mythos

Anthropic's buzzy announcement about using AI to improve cybersecurity earlier this month was met with plenty of skepticism. However, Mozilla shared some details that...

SpaceX and Cursor strike partnership that might end in a $60 billion acquisition

SpaceX and AI company Cursor have struck a new partnership that could see the owner of X buy the AI company for $60 billion...

Google Wallet adds Live Update for flight tracking

As previously teased, Google Wallet for Android now offers Live Updates for tracking your current flight. Read more @ 9to5google

The AirPods are Tim Cook’s most underrated achievement

The AirPods changed the direction of true wireless earbuds and became Apple’s most important accessory. | Photography by Amelia Holowaty Krales / The Verge Apple...

Framework is building a better couch keyboard because everyone hates the Logitech one

If you have a wireless keyboard with a touchpad that lets you control your PC from across the room, chances are it's a Logitech...

Framework’s first eGPUs turn its laptop into a desktop PC

Remember when Framework made the first laptop where you can easily upgrade its entire internal video card in three minutes flat? The company's getting...