September 26, 2023

Dell pushing out a massive number of updates with more than one hundred models impacted by newly-disclosed BIOS/UEFI vulnerabilities.

Eclypsium has discovered multiple vulnerabilities around Dell’s “BIOSConnect” feature within their BIOS/UEFI. These vulnerabilities could lead to a privileged network adversary impersonating and gaining arbitrary code execution support at the BIOS/UEFI level. Some 128 different Dell models across their consumer and business devices are believed to be impacted.

This pre-boot remote execution code discovery can happen even on systems with Secure Boot enabled and other features.

Dell has been publishing updated BIOS/UEFI for not only their Windows customers but also posting the new firmware to LVFS so it can be deployed quickly on Linux. Those with Dell desktops and laptops should run sudo fwupdmgr update as soon as possible

