Tag: UEFI

3 articles
Date Tue 11 February 2025
Author Gwaby
Category Exploitation

In this blog post we explain the consequences of asking our R&D boss for a Steam Deck as a Christmas gift. It involves a couple of vulnerabilities, limited primitives, challenging exploitation and a long disclosure process.

Date Tue 16 January 2024
Authors Francisco Falcon, Iván Arce
Category Vulnerability

This blog post provides details about nine vulnerabilities affecting the IPv6 network protocol stack of EDK II, TianoCore's open source reference implementation of UEFI.

Date Fri 23 June 2023
Author Gwaby
Category Exploitation

In this blog post we'll see a technique to gain code execution in SMM from a very limited write primitive.