Live data from Hacker News

ThinkPwn: System Management Mode arbitrary code execution

github.com

11–20 of 154 posts

Re: ThinkPwn: System Management Mode arbitrary code execution

#11
post #5

Starting with the X230 series of ThinkPads, Lenovo has used flash write protection to prevent "unauthorized" BIOS modifications. Owners of X220 laptops and below are able to reflash the BIOS to remove Lenovo's whitelist of WLAN/WWAN cards; the X230 models are currently stuck with Wi-Fi N and Gobi 3000 3G-only cards due to Lenovo's whitelist. Would this exploit allow ThinkPad owners to reflash their BIOS chip without…

Most likely not; the flash protection is not done by the firmware, but by the Intel Management Engine and a public key burnt into silicon (Intel Boot Guard). The current exploit only runs far later, after the validation is performed. So unless you manage to mangle the code execution flow of the authentic firmware to the point that it skips the whitelists, you can't get rid of it.

On X220 and previous, the whitelist is removed by creating a modified version of the BIOS without the included whitelist, then flashing it to the BIOS chip. Technically, this can still be done on X230, but as it has the flash write disable unless a signed Lenovo image is to be flashed, the user must desolder the BIOS chip and flash it with the modified image using an SPI chip flasher. As this exploit can remove this flash write protection, perhaps a modified BIOS image can be flashed from the system itself, bypassing the Lenovo signature check?

Re: ThinkPwn: System Management Mode arbitrary code execution

#12
> Vulnerable code of SystemSmmRuntimeRt UEFI driver was copy-pasted by Lenovo from Intel reference code for 8-series chipsets.

> Alex James found vulnerable code on motherboards from GIGABYTE (Z68-UD3H, Z77X-UD5H, Z87MX-D3H, Z97-D3H and many others):

This is beyond the scope of just Lenovo machines.

Re: ThinkPwn: System Management Mode arbitrary code execution

#13

> Vulnerable code of SystemSmmRuntimeRt UEFI driver was copy-pasted by Lenovo from Intel reference code for 8-series chipsets. > Alex James found vulnerable code on motherboards from GIGABYTE (Z68-UD3H, Z77X-UD5H, Z87MX-D3H, Z97-D3H and many others): This is beyond the scope of just Lenovo machines.

As confirmed by Lenovo as well:

> The package of code with the SMM vulnerability was developed on top of a common code base provided to the IBV by Intel. Importantly, because Lenovo did not develop the vulnerable SMM code and is still in the process of determining the identity of the original author, it does not know its originally intended purpose. But, as part of the ongoing investigation, Lenovo is engaging all of its IBVs as well as Intel to identify or rule out any additional instances of the vulnerability's presence in the BIOS provided to Lenovo by other IBVs, as well as the original purpose of the vulnerable code.

https://support.lenovo.com/ca/en/solutions/LEN-8324

Re: ThinkPwn: System Management Mode arbitrary code execution

#14
post #4

Interesting bit form Lenovo's security advisory on the matter[0]: > Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information. [0] https://support.lenovo.com/us/en/solutions/LEN-8324

Clear as mud.

Lenovo has previously sacrificed user security and privacy for money (superfish), so it does not surprise me that they have done it again, and these kinds of weasel words aren't going to get me to buy another Lenovo product again.

Here's an idea: How about not putting backdoors in our products?

How about making it easier for consumers to replace software on systems they own?

Re: ThinkPwn: System Management Mode arbitrary code execution

#15

Starting with the X230 series of ThinkPads, Lenovo has used flash write protection to prevent "unauthorized" BIOS modifications. Owners of X220 laptops and below are able to reflash the BIOS to remove Lenovo's whitelist of WLAN/WWAN cards; the X230 models are currently stuck with Wi-Fi N and Gobi 3000 3G-only cards due to Lenovo's whitelist. Would this exploit allow ThinkPad owners to reflash their BIOS chip without…

You can reflash in place (no need for desoldering) using a SO8 clip. Did that on a T430.

Re: ThinkPwn: System Management Mode arbitrary code execution

#16

Starting with the X230 series of ThinkPads, Lenovo has used flash write protection to prevent "unauthorized" BIOS modifications. Owners of X220 laptops and below are able to reflash the BIOS to remove Lenovo's whitelist of WLAN/WWAN cards; the X230 models are currently stuck with Wi-Fi N and Gobi 3000 3G-only cards due to Lenovo's whitelist. Would this exploit allow ThinkPad owners to reflash their BIOS chip without…

My coworker replaced his BIOS/UEFI with an open source version (thinkpads enable this). It allowed him bypass Lenovo’s whitelisting of “approved” hardware, so he could install his own 3g modem.

He repurposed an old Arduino into an SPI flasher and a chip clip to sit on the bios flash chip.

https://twitter.com/thomas_cannon/status/703633676102471680

Re: ThinkPwn: System Management Mode arbitrary code execution

#17

T450S user here. What exactly does this mean for me? I get it's a security issue, but that's about all I understood...

The example exploit is run from an UEFI shell which requires physical control of the device. It mentions exploitation from the OS as a possibility however one would expect that the OS shouldn't allow such operations as a non root user.

Re: ThinkPwn: System Management Mode arbitrary code execution

#18
post #6
post #2

Really hope Lenovo respond soon. Feel like I should leave my ThinkPads hibernated for now.

I think this exploit requires local administrative access. If an attacker already has this, you're pretty screwed to begin with. In other words, while this could definitely make an attack more damaging and harder to remove, it doesn't seem like a reason to stop using a computer that has decent software and physical security.

This exploit just requires physical, not administrative, access to the machine. You build an EFI "app", put it on a flash drive, and execute it from the UEFI shell.

Re: ThinkPwn: System Management Mode arbitrary code execution

#19
post #4

Interesting bit form Lenovo's security advisory on the matter[0]: > Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information. [0] https://support.lenovo.com/us/en/solutions/LEN-8324

Maybe author did not want to deal with Lenovo.

> Lenovo did not develop the vulnerable SMM code and is still in the process of determining the identity of the original author, it does not know its originally intended purpose.

Re: ThinkPwn: System Management Mode arbitrary code execution

#20
post #9

What are we up to now? Three preloaded spyware scandals, possible remote execution via the Intel stack and now this vulnerability. That's just what we know about, who knows what else exists. I don't think I can buy another one, which is sad as I think it was a timeless and great design.

I plan on using my quad core T520 for probably another 5+ years. All of their laptops after the T520 series have the full size keyboard with numberpad which off-sets the center of the keyboard, so now your typing is mostly happing on the left side of the keyboard and that causes wrist strain.

Having a numberpad is really lame on a laptop. I won't buy one and I know of no one else that likes the numberpad either.. sadly many manufactures are doing the same.

Post reply on HN