3 ms·
If a local vulnerability that requires administrative privileges to exploit is "high impact", I wonder how they would classify remote code execution. Super dupe
by peppermint_gum 3y ago
If a local vulnerability that requires administrative privileges to exploit is "high impact", I wonder how they would classify remote code execution. Super duper high impact?
This of course needs to be patched, but it's way overblown. This vulnerability alone provides no attack vector, you need other vulnerabilities to be able to replace the logo.
- gunapologist99 3y agoBut an RCE goes away as soon as you re-OS. Once your UEFI is pwned, you might as well pitch the box in the rubbish bin.
- planede 3y agoThe attack defeats the whole premise of security in "secure boot". It's high impact in relation to that. As a user I don't care too much about "secure boot" and its threat model, and I assume you don't either.