UPDATED 13:00 EDT / JULY 29 2020

SECURITY

Newly discovered Linux and Windows vulnerability opens the door to hackers

A newly discovered serious vulnerability that affects most Linux and Windows installations, including servers, opens the door to hackers to run riot.

Discovered by security researchers at enterprise device security firm Eclypsium Inc. and revealed today, the “BootHole” vulnerability resides in the GRUB2 bootloader utilized by most Linux systems. GRUB2, the latest version of GNU GRUB is the first software program that runs when a computer starts. With Linux installations, it’s responsible for loading and transferring control to the operating system kernel.

BootHole exploits a vulnerability in GRUB2 to gain arbitrary code execution during the boot process, even when Secure Boot is enabled. Attackers exploiting this vulnerability are said to be able to install persistent and stealthy bootkits or malicious bootloaders that could give them near-total control over the victim device.

The vulnerability is also said to affect systems using Secure Boot, even if they are not using GRUB2. Nearly all signed versions of GRUB2 are vulnerable meaning virtually every Linux distribution is affected. In addition, GRUB2 supports other operating systems, kernels and hypervisors such as Xen.

It gets worse yet: The researchers said the vulnerability extends to any Windows device that uses Secure Boot with the standard Microsoft Corp. Third Party UEFI Certificate Authority. “Thus the majority of laptops, desktops, servers and workstations are affected, as well as network appliances and other special purpose equipment used in industrial, healthcare, financial and other industries,” the researchers said.

Eclypsium has already contacted operating system providers and computer manufacturers. Mitigation of the vulnerability requires new bootloaders to be signed and deployed, and vulnerable bootloaders should be revoked to prevent adversaries from using older, vulnerable versions in an attack. “This will likely be a long process and take considerable time for organizations to complete patching,” the researchers noted.

Image: Eclypsium

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.