Researchers Identify Weakness in Microsoft WPBT
eclypsium.com
eclypsium.com
I remember looking at WPBT years ago as a possible means to achieve cloud-init -like functionality for Windows VMs being deployed on bhyve.
While there is no official mitigation, what's being proposed seems to be modifying the firmware to block vendor content when the code signing certificate is expired. I wonder, what does that mean if I pull mid 2000s ThinkPad out of a dumpster? Assuming WPBT would be handling stuff that's been signed by an expired certificate, would it then boot without the necessary drivers? Could this be a problem for, say, computers preserved for historical reasons, or for evidence/forensics?
So, good luck modifying those ACPI tables to get rid of that crap.
It's frustrating to see more and more control of our machines being taken away and hidden under layers of firmware/hardware/closed source code - especially if it's exploitable like this... It seems like a very short-sighted bug!
However, I could see this feature being somewhat helpful for OEMS (Dell/HP deploying their "support assist" softwares for their devices if it's uninstalled/new copy of Windows.
maybe? the other option is through window's auto driver update feature, which also runs arbitrary code. see: https://news.ycombinator.com/item?id=28273283
Reinstall Windows from a clean official Microsoft image? That shit is still in there.
And it should be safe to assume laptops sold in some countries like China do bundle literal state-mandated rootkits in there.
In other sectors of the consumer space, they make updates that make the rootkits not work anymore.