Warning: ‘Hundreds Of Millions At Risk’ From 12-Year-Old Vulnerabilities Lying Deep In Dell PCs

  • 📰 Forbes
  • ⏱ Reading Time:
  • 69 sec. here
  • 3 min. at publisher
  • 📊 Quality Score:
  • News: 31%
  • Publisher: 53%

United States Headlines News

United States Latest News,United States Headlines

For 12 years, some “high severity” weaknesses have been resident in a component that’s run on Dell PCs running Microsoft Windows

... [+], a cybersecurity company has warned. The vulnerabilities require that a hacker already have some level of access to an affected computer, but allow them to gain almost total control of the PC. Hundreds of millions of devices are at risk and should patch on Tuesday, as Dell has released an update for its customers.

The weaknesses lay in the BIOS, the code responsible for launching the PC and its operating system. If a hacker can gain control over that section of a computer, in what’s also referred to as gaining kernel-level privileges, they can do almost anything they want to the PC, whether that’s locking up all the files within, destroying them or installing code that spies on all user activity.

Five vulnerabilities were discovered by researchers from cybersecurity firm SentinelOne in a driver for Dell PCs’ BIOS, in particular the DBUtil driver. It normally installs and runs during a BIOS update to allow the code to communicate with the hardware. Though SentinelOne isn’t providing full details of its findings to allow Dell and its users time to update, in a research report handed toahead of publication, one of the most obvious issues with the driver is that it allows any process to communicate with it, which “is often a bad practice since drivers operate with the highest of privileges.”

The weaknesses were first reported to Dell in December 2020. The researcher who discovered the issues, Kasif Dekel, said that one of the most obvious abuses of such vulnerabilities would be to “bypass security products.” “The impact this could have on users and enterprises that fail to patch is far-reaching and significant,” he wrote in his research report.

 

Thank you for your comment. Your comment will be published after being reviewed.
Please try again later.
We have summarized this news so that you can read it quickly. If you are interested in the news, you can read the full text here. Read more:

 /  🏆 394. in US

United States Latest News, United States Headlines

Similar News:You can also read news stories similar to this one that we have collected from other news sources.

FDA Expands Pfizer Coronavirus Vaccine Authorization For AdolescentsAnyone 12 years old or older will be able to get the jab.
Source: Forbes - 🏆 394. / 53 Read more »

FDA Expands Pfizer Coronavirus Vaccine Authorization For AdolescentsThe FDA said it would expand its emergency use authorization of the Pfizer-BioNTech coronavirus vaccine to include adolescents Fantastic news! And just got my second dose today and 💉
Source: Forbes - 🏆 394. / 53 Read more »

Retiring therapy dog receives heartwarming standing ovation from hospital staffRetiring therapy dog Tassy was applauded by staff at the Doctors Medical Center in Modesto, California on Wednesday. In a press release, the center said 12-year-old Tassy had been volunteering with them for more than eight years.
Source: Newsweek - 🏆 468. / 52 Read more »

12-year-old shares her experience as part of Duke University Pfizer vaccine trial'I just really wanted a way to help out all of the community and a way to get out of this pandemic so that we can all be safe and go back to normal lifestyles,' 12-year-old Sophie Holland says why she participated in the Duke Pfizer vaccine trial.
Source: MSNBC - 🏆 469. / 51 Read more »

Yahoo Back On Top After Purchasing Millions Of 13-Year-Old Girls’ BlogsSUNNYVALE, CA—Finally overcoming competition from the likes of Google, Microsoft, and AOL, internet corporation Yahoo firmly re-secured its place as an industry leader after Sunday’s purchase of millions of blogs written by 13-year-old girls. “While Yahoo has seen its share of struggles over the years, the company’s acquisition of over 100 million blogs written by middle-school females before bedtime has already majorly revitalized the company’s brand,” said BCG consultant Timothy Shore, praising the $1.1 billion purchase of web pages filled with complaints about parents, speculation about cute boys in school, and photos of Robert Pattinson. “Yahoo is looking to the future here, and tying the entire life of their company to a bunch of pubescent girl bloggers was the smart move.” Yahoo has projected that 13-year-old Melissa Wheeler’s blog, mellisasworld.tumlbr.com, would eventually pull in over $2.3 billion for the company. apexnerd At least it only sold for $5 billion this time around. nO WAY
Source: TheOnion - 🏆 724. / 51 Read more »