Live data from Hacker News

ThinkPwn: System Management Mode arbitrary code execution

github.com

1–10 of 154 posts

Re: ThinkPwn: System Management Mode arbitrary code execution

#3
Starting with the X230 series of ThinkPads, Lenovo has used flash write protection to prevent "unauthorized" BIOS modifications. Owners of X220 laptops and below are able to reflash the BIOS to remove Lenovo's whitelist of WLAN/WWAN cards; the X230 models are currently stuck with Wi-Fi N and Gobi 3000 3G-only cards due to Lenovo's whitelist. Would this exploit allow ThinkPad owners to reflash their BIOS chip without desoldering and flashing with external hardware?

Re: ThinkPwn: System Management Mode arbitrary code execution

#4
Interesting bit form Lenovo's security advisory on the matter[0]:

> Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information.

[0] https://support.lenovo.com/us/en/solutions/LEN-8324

Re: ThinkPwn: System Management Mode arbitrary code execution

#5

Starting with the X230 series of ThinkPads, Lenovo has used flash write protection to prevent "unauthorized" BIOS modifications. Owners of X220 laptops and below are able to reflash the BIOS to remove Lenovo's whitelist of WLAN/WWAN cards; the X230 models are currently stuck with Wi-Fi N and Gobi 3000 3G-only cards due to Lenovo's whitelist. Would this exploit allow ThinkPad owners to reflash their BIOS chip without…

Most likely not; the flash protection is not done by the firmware, but by the Intel Management Engine and a public key burnt into silicon (Intel Boot Guard).

The current exploit only runs far later, after the validation is performed. So unless you manage to mangle the code execution flow of the authentic firmware to the point that it skips the whitelists, you can't get rid of it.

Re: ThinkPwn: System Management Mode arbitrary code execution

#6
post #2

Really hope Lenovo respond soon. Feel like I should leave my ThinkPads hibernated for now.

I think this exploit requires local administrative access. If an attacker already has this, you're pretty screwed to begin with.

In other words, while this could definitely make an attack more damaging and harder to remove, it doesn't seem like a reason to stop using a computer that has decent software and physical security.

Re: ThinkPwn: System Management Mode arbitrary code execution

#9
What are we up to now? Three preloaded spyware scandals, possible remote execution via the Intel stack and now this vulnerability. That's just what we know about, who knows what else exists. I don't think I can buy another one, which is sad as I think it was a timeless and great design.
Post reply on HN