Critical DMA Boot Vulnerability Hits ASRock, ASUS, GIGABYTE, MSI Boards

Critical DMA Vulnerabilities in ASRock, ASUS, GIGABYTE, and MSI Motherboards Enable Pre-OS Memory Attacks; Firmware Updates Urgently Required

  • Multiple motherboard models from major vendors have a vulnerability allowing direct memory access (DMA) attacks during early boot.
  • The issue involves failure to properly enable the input–output memory management unit (IOMMU), despite firmware indicating active DMA protection.
  • The flaw enables physical attackers to read or modify system memory before the operating system loads.
  • Four vulnerabilities impacting ASRock, ASUS, GIGABYTE, and MSI motherboards have been identified, each with a CVSS score of 7.0.
  • Firmware updates to fix the IOMMU initialization and enforce DMA protections are now available and should be applied promptly.

Certain motherboards from ASRock, ASUSTeK Computer, GIGABYTE, and MSI are exposed to security vulnerabilities that allow direct memory access (DMA) attacks during the early boot phase. These flaws were identified in models implementing the Unified Extensible Firmware Interface (UEFI) and the input–output memory management unit (IOMMU). The vulnerabilities were publicly reported on December 19, 2025.

- Advertisement -

UEFI is firmware designed to initialize hardware and load the operating system, while IOMMU restricts peripheral devices from unauthorized memory access. The issue involves a mismatch between the firmware’s indication that DMA protection is active and the actual failure to correctly initialize IOMMU during boot. According to the CERT Coordination Center (CERT/CC), this gap enables a malicious PCIe device with physical access to read or manipulate system memory before OS-level protections are in place. This undermines boot process integrity and could expose sensitive data or allow pre-boot code injection.

The identified vulnerabilities include:

  • CVE-2025-14304 affecting ASRock boards using Intel 500–800 series chipsets.
  • CVE-2025-11901 impacting ASUS motherboards with Intel Z490 to W790 series chipsets.
  • CVE-2025-14302 targeting GIGABYTE models with Intel Z890 to W790 and AMD X870 to TRX50 series chipsets (a fix for TRX50 is planned for Q1 2026).
  • CVE-2025-14303 found in MSI motherboards using Intel 600 and 700 series chipsets.

Each vulnerability is rated with a Common Vulnerability Scoring System (CVSS) score of 7.0, indicating a high severity level.

Affected vendors have released firmware updates addressing the proper initialization of IOMMU and enforcement of DMA protections during boot. Users and system administrators are strongly encouraged to apply these updates immediately. “In environments where physical access cannot be fully controlled or relied on, prompt patching and adherence to hardware security best practices are especially important,” stated CERT/CC. The organization also emphasized that correct firmware configuration is critical even for systems outside of data center use, given the role of IOMMU in virtualization and cloud environments.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Bitcoin Holds at $92K Amid Trade Tensions, Volatility Fears.

Bitcoin stabilized near $92,000 after a liquidation-driven sell-off on Monday.Options markets show rising demand...

Trove Keeps $9.4M for Solana Pivot; Investors Demand Refunds

Trove Markets will keep about $9.4 million of an over $11.5 million raise and...

BTC retreats to $92K as $395M ETF outflows, gold soars anew.

Bitcoin fell 3.4% over the weekend as investors cut risk amid geopolitical tensions and...

Burwick Law seeks sanctions, compliance monitor for Pump Fun

Burwick Law asked a judge to stop the memecoin platform Pump Fun from Hosting...

Bermuda to launch nation-wide on-chain economy with USDC now

Bermuda plans to move much of its economy on-chain with support from Coinbase and...
- Advertisement -

Must Read

What Are Sniper Bots Used in Defi Trading?

You've heard about DeFi, but what about sniper bots? These high-speed trading tools are shaking up the crypto scene.But don't fret, you're not...
Bitcoin (BTC) $ 92,232.00 0.35%
Ethereum (ETH) $ 3,180.69 0.86%
XRP (XRP) $ 1.96 0.43%
Bittensor (TAO) $ 249.34 0.89%
Polkadot (DOT) $ 2.02 2.44%
Cardano (ADA) $ 0.36628 0.44%
Chainlink (LINK) $ 12.83 0.04%
Hyperliquid (HYPE) $ 23.72 1.06%
Monero (XMR) $ 606.66 0.13%
Hedera (HBAR) $ 0.110052 0.78%
Toncoin (TON) $ 1.56 3.41%