GPU VulnDB

Database/Firmware, BMC & network fabric

Gigabyte UEFI firmware (OEM update-dropper in firmware): Gigabyte firmware shipped a UEFI module that writes a Windows

NCVD-2023-001-gigabyte-uefi-firmware-oem-updatFirmware, BMC & network fabricGigabyte App Center backdoorcurated

Impact

Gigabyte firmware shipped a UEFI module that writes a Windows executable to disk at every boot and has it fetch and run further code from Gigabyte-controlled URLs - one of them plain HTTP, with weak certificate validation on the others. It is not malware, it is the vendor's own updater, but it behaves exactly like a firmware implant: an unremovable, boot-persistent downloader with no user consent and no way to disable it from the OS. Anyone who can MITM that fetch, or who compromises the vendor's distribution point, gets code execution on every affected machine at every boot.

Who can reach it

A network attacker in path of the update fetch, or a supply-chain compromise of the vendor endpoint. No access to the machine needed.

What to do

Gigabyte published firmware updates that fix the transport and validation; applying them is a per-board BIOS flash plus reboot. Where the platform allows it, disable the 'APP Center Download & Install' option in BIOS setup - a config-only mitigation you can push faster than a firmware campaign. The broader operator lesson: audit what your board vendor's firmware talks to on the network before a node ever carries tenant workload, and block outbound egress from the provisioning network by default.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.