CVE-2018-12169 also potentially allows a developer to "jailbreak" their BootGuard protected laptop since the UEFI DXE volume can be replaced with a user provided LinuxBoot ROM image. https://www.linuxboot.org/ pic.twitter.com/MeWI0DGUBf
U tweetove putem weba ili aplikacija drugih proizvođača možete dodati podatke o lokaciji, kao što su grad ili točna lokacija. Povijest lokacija tweetova uvijek možete izbrisati. Saznajte više
CVE-2018-12169 also potentially allows a developer to "jailbreak" their BootGuard protected laptop since the UEFI DXE volume can be replaced with a user provided LinuxBoot ROM image. https://www.linuxboot.org/ pic.twitter.com/MeWI0DGUBf
Meant to ask (but was too lazy to look up the older post until now). Was this, this: https://twitter.com/qrs/status/1006307586189283328 … ?
CVE-2018-12169 and CVE-2018-9062 are fairly simple: some FV not covered by BootGuard or vendor hashes are searched for executables by PeiCore. The TOCTOU issue isn't fully developed yet, looks like a post-ACM BootGuard issue and possibly a ME vulnerability.pic.twitter.com/WIfRumQQPv
Great work.
Any more details? Or is the embargo you mentioned on #osfc still active?
Too bad it does not affect Apollo Lake, would have liked to „jailbreake“ my compulab‘s fitlet2.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.