THREATOPS
THREAT OPSThreat News › PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem

PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem

infobinarlyPublished 2024-07-25

PKfail is a zero day disclosure detected by the Binarly REsearch Team. PKfail is a firmware supply-chain issue affecting hundreds of device models in the UEFI ecosystem. The problem arises from the Secure Boot "master key," known as the Platform Key (PK) in UEFI terminology, which is untrusted because it is generated by Independent BIOS Vendors (IBVs) and shared among different vendors.

Original source: https://www.binarly.io/blog/pkfail-untrusted-platform-keys-undermine-secure-boot