Certain motherboard models from ASRock, ASUSTeK Computer, GIGABYTE, and MSI have been identified as vulnerable to a security flaw that exposes systems to early-boot direct memory access (DMA) attacks. The issue affects platforms that rely on Unified Extensible Firmware Interface (UEFI) firmware in conjunction with an input–output memory management unit (IOMMU), both of which are intended to establish a secure hardware trust boundary before the operating system loads. The vulnerability was discovered by Riot Games researchers Nick Peterson and Mohamed Al-Sharifi and arises from an inconsistency in how certain UEFI implementations handle DMA protection status. Although the firmware reports that DMA protections are enabled, it fails to correctly initialize and activate the IOMMU during a critical early-boot window. According to the CERT Coordination Center (CERT CC), this misconfiguration allows a malicious Peripheral Component Interconnect Express (PCIe) device with physical access to the system to perform unrestricted memory access before operating system-level security controls are in place. An attacker could exploit this gap to read sensitive memory contents, alter system state, or influence the boot environment, effectively undermining the system’s chain of trust prior to kernel initialization. Exploitation of the flaw could enable pre-boot code injection and unauthorized memory manipulation on systems running unpatched firmware. The issue has been assigned multiple CVEs, including CVE-2025-14304 affecting ASRock platforms, CVE-2025-11901 impacting ASUS systems, CVE-2025-14302 covering a broad range of GIGABYTE Intel and AMD chipsets, and CVE-2025-14303 for MSI Intel 600 and 700 series motherboards. Affected vendors are releasing firmware updates to correct the IOMMU initialization sequence and ensure DMA protections remain enforced throughout the boot process. CERT CC strongly recommends applying these updates promptly, particularly in environments where physical access cannot be tightly controlled or where systems support virtualization and cloud workloads, as proper firmware configuration is essential to maintaining foundational hardware security.
Cybercriminals are now weaponizing legitimate hotel reservation data to trick travelers into surrendering their payment details. This "Reservation Hijack Scam" stands out b...
A serious security issue has been discovered in nginx-ui, which can allow attackers to take full control of a system. This vulnerability is tracked as CVE-2026-33026. The problem e...
A sophisticated phishing campaign is targeting Spanish speaking users across Latin America and Europe, aiming to deploy Windows banking malware such as Casbaneiro (also known as Me...