Bypasses for #UEFI file security don't come around often, and when the do, they can be confusing. @HexKitchen offers his analysis of one such bypass (CVE-2021-26892) in his latest blog.https://www.zerodayinitiative.com/blog/2021/6/30/cve-2021-26892-an-authorization-bypass-on-the-microsoft-windows-efi-system-partition …
Replying to @thezdi @HexKitchen
Jonas L Retweeted Jonas L
and that is just continuation ofhttps://twitter.com/jonaslyk/status/1316101042279452673?lang=en …
Jonas L added,
Jonas L @jonasLyk
CVE-2020-16938 WRITEUP- aka how I installed an UEFI bootkit from edge sandbox.
So- the UEFI partition runs FAT32( No ACL or owner concepts)- so instead access is controlled virtually.
Thing is though- by just requesting MAX for permissions everything is bypassed and you get write pic.twitter.com/qcCZKFU6pg
9:42 AM - 30 Jun 2021
0 replies
0 retweets
5 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.