UNSOLVED

SteveCRF

updated

5 years ago

S

SteveCRF

2 Posts

0

3205

May 24th, 2021 01:00

Five High-Severity BIOS Driver Privilege Escalation Vulnerabilities

Hi folks,

* We are a small volunteer run charity, dependent on equipment donations for the tech we use to keep the organisation running

* Presently we have a business desktop estate of approx 115 PCs

* Most of these are Dell 7010s & 7010s (we still have a few 790s but a recent donation of more 7010s & 7020s meaning we are targeting removing the last of the 790s from the estate)

* Can anyone with expertise in these Dell PCs help please with advice on:

a) The exposure this threat presents to the PC models I describe

b) Actions we should take specific to the PC models I describe

Any help is appreciated.

Rgds,

Steve

  • speedstep

    11 Legend

    46969 Posts

    1681

    0

    Posted May 24th, 2021 07:00

    No Idea what the 5 are.

    BIOS SETUP REQUIRING password is easy.

    Most of the vulnerabilities can be disabled by restricting local physical access and locking covers with Kensington locks.

  • bradthetechnut

    9 Technologist

    9649 Posts

    40713 Points

    1645

    0

    Posted May 24th, 2021 13:00

    I also Googled your subject line.  Please let us know if you need to know anything in regards to the results.  It does mention Dell rolled out security patches.

  • bradthetechnut

    9 Technologist

    9649 Posts

    40713 Points

    1647

    0

    Posted May 24th, 2021 13:00

    Hi @SteveCRF ,

    For the 7020:  https://www.dell.com/support/home/en-us/product-support/product/optiplex-7020-desktop/drivers 

    Optiplex 7020 Win10 Driver Pack 

    7010:  https://www.dell.com/support/home/en-us/product-support/product/optiplex-7010/drivers 

    Optiplex 7010 Win10 Driver Pack 

    Just giving 2 different ways to update drivers so you're aware of both methods.  Driver pack if starting fresh or individual drivers if needed.

    Make sure you have the latest BIOS for your Optiplex.  A29 for the 7010.  Not sure for the 7020.  I got a couple of different #'s depending on how I went into website.  Possibly A18?  If you're looking to lower possible security risks, th latest BIOS helps that.  Keep in mind it won't be 2021 BIOS, but the latest that was rolled out for your system.

    I could only ascertain an idea of what you are looking for from your post.

    Of course, 115 PC's doesn't sound small.  However, whatever size you are, organisation, small or large business with out of warranty PC's, or individual, you're welcome to get help here.  People sometimes come here for in warranty PC's also.  (Just didn't want to rule them out.)

    I don't have a way of updating drivers and BIOS on 115 PC's all at the same time though.  Another community member or Rockstar might or might not.  (115 people?)

    Hopefully this helps.  Please let us know if you have any further questions.

  • speedstep

    11 Legend

    46969 Posts

    1640

    0

    Posted May 24th, 2021 14:00

    Keep in Mind

    Intel isn’t going to patch some of its older CPUs which are vulnerable to the Meltdown and Spectre flaws, according to an update issued. Bloomfield, Clarksfield, Gulftown, Harpertown,  Xeon C0 and E0, Jasper Forest, Penryn, SoFIA 3GR, Wolfdale and Yorkfield families (and Xeon variants).


    I beleive Intel gave up on patching these systems because neither motherboard makers nor Microsoft are willing to update systems sold more than a decade ago.

    GRC has a test utility to see if you have an issue.
    https://www.grc.com/inspectre.htm

     

  • bj11213

    77 Posts

    1570

    0

    Posted May 25th, 2021 01:00

    Nothing much to add to that except to remark that updating BIOS is (IMHO) very much a matter of last resort ... not only is there a (small, if you download the new BIOS from a reputable source) chance of introducing new vulnerabilities but also a fair chance of bricking the motherboard.

     

    You can get a good degree of protection from unpatched vulnerabilities by running firewall on the gateway between you local network and the internet. Also vulnerabilities thrive on monocultures so it is wise to deploy a mix of different brands & models rather than all being the same, and a mix of operating systems too, especially if you're a medium to large organisation which might find itself the target of a directed attack.

     

    I appreciate that this strategy causes complications in supporting unskilled users, but as always a compromise has to be found between security and convenience.

  • speedstep

    11 Legend

    46969 Posts

    1545

    0

    Posted May 25th, 2021 07:00

    The first obfuscated URL is EXIF XSS malware

    That post will be deleted.

    https://umbrella.cisco.com/blog/picture-perfect-how-jpg-exif-data-hides-malware

    https://    images .content.hello.global.ntt /Web/NTTLimited/  %7B116077f6-59ca-48ea-a53d-33bd7a97094c%7D   _GTIC-SB-202012-002_Trickbot_Firmware_Vulnerability_Module.pdf?   elqTrack = true

  • bradthetechnut

    9 Technologist

    9649 Posts

    40713 Points

    1515

    0

    Posted May 25th, 2021 11:00

    "if you download the new BIOS from a reputable source)"  I've only downloaded BIOS from the Dell site, which is where my links go to.  Not sure if bj11213 has had MB's brick, but updating BIOS is a common practice.  A motherboard may brick if power goes out while updating, and those chances are rare depending on where you are.  And I wouldn't update it during a storm.

    It's also wise to update BIOS if updating hardware.  There's been situations where new hardware wouldn't work until updating BIOS.  So bj11213 and I differ there.

    With any luck, those PC's will already have the latest BIOS, as the latest BIOS for them isn't too new.

  • bradthetechnut

    9 Technologist

    9649 Posts

    40713 Points

    876

    0

    Posted May 25th, 2021 12:00

    Hi @bj11213,

    What units did you mainly see brick with BIOS updates, Dell, HP, etc., old or new?

    I could tell you have much, much experience with PC's.

    Also, I've never used external methods for updating BIOS.

    Sorry to hear about the Netgear trouble.

    And we've had it too in this forum, I think rarely, whereas a BIOS update bricked MB.

  • bradthetechnut

    9 Technologist

    9649 Posts

    40713 Points

    1507

    0

    Posted May 25th, 2021 12:00

    Another point of course is the internet connection has to be reliable and not interrupt.

  • bj11213

    77 Posts

    1506

    0

    Posted May 25th, 2021 12:00

    In a previous life I've been in computer support & yes, I've seen a lot of PCs which have been bricked by users trying to upgrade BIOS, mostly when they didn't need to ... mostly those who will accept "the right file" on a floppy disk / CD-ROM / USB stick from a colleague without bothering to check, but it's still quite easy to get the wrong file from the official source unless you're sober, well rested and paying attention.

     

    I've also had seen BIOS downloads from the manufacturer's site for the correct motherboard foul up without the aid of a power glitch & these events are usually terminal. I'd strongly suggest powering the unit from a RELIABLE UPS with surge suppressed output whilst doing things as critical as BIOS update but it's no guarantee of a successful outcome.

     

    And I spent most of last weekend recovering a (Netgear) network attatched storage unit from a severe issue caused by a firmware update (which is still on line. If by any chance you have a ReadyNAS unit do NOT upgrade to 6.10.5, you will lose control of the unit through the web interface & it's hard to control it any other way or backtrack to 6.10.4 unless you have enabled direct access by SSH, which is a pretty large security risk in its own right). The Netgear support boards are full of customers complaining of bricked units; maybe the company is trying desperately to sell replacement units!

     

    Of course a BIOS upgrade MAY be necessary to support new / upgraded hardware but there is a significant risk attached and I'm going to stick rigidly to "don't, unless there is no other option".

     

    Four decades ago when I began my association with PC hardware & operating systems the BIOS was in a socketed ROM chip; on the (more frequent than now) occasions when a patch was necessary you just obtained (or programmed yourself) a new ROM & swapped the chips with the power off. Relatively safe, very easy to backtrack. The "modern" way is more or less an invitation to allow malware into the system; I don't know why things changed, but "progress" isn't always in a forward direction.