Finding SMM Privilege-Escalation Vulnerabilities in UEFI Firmware with Protocol-Centric Static Analysis
Jiawei Yin, Menghao Li, Wei Wu, Dandan Sun, Jianhua Zhou, Wei Huo, Jingling Xue
Abstract
The Unified Extensible Firmware Interface (UEFI) provides a specification of the software interface between an OS and its underlying platform firmware. The runtime services provided are seemingly secure as they reside in System Management Mode (SMM) at ring -2, assuming a higher privilege than the OS kernel at ring 0. However, their software vulnerabilities are known to be exploitable to launch ring 0 to ring -2 privilege escalation, i.e., SMM privilege escalation attacks.In this paper, we introduce an effective static analysis framework for detecting SMM privilege escalation vulnerabilities in UEFI firmware. We present a systematic study of such vulnerabilities and identify their root causes as being two types of references that can escape from the SMRAM, legacy references and unintentional references. Existing static analyses are ineffective in detecting such vulnerabilities in stripped COTS UEFI firmware images, which are developed based on a customized callback mechanism that organizes callable functions into protocols identified by GUIDs. By leveraging such a callback-based programming paradigm, we introduce SPENDER, the first static detection framework, which is founded on a novel protocol-centric analysis, for uncovering the potential SMM privilege escalation vulnerabilities in UEFI firmware efficiently and precisely. For a total of 1148 UEFI binaries collected from eight vendors, SPENDER has successfully found 36 SMM privilege escalation vulnerabilities (two 1-day and 34 0-day vulnerabilities), which can cause arbitrary code execution and arbitrary address write (and can thus enable, e.g., the attackers to install a bootkit into a flash drive). We have reported these 36 vulnerabilities to the vendors, with the two 1-day vulnerabilities confirmed as known previously but the 34 0-day vulnerabilities confirmed as new.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5c92bca5-a4aa-4f3a-82cf-be3216d5e6e0Cited by top-tier papers7
- Your Firmware Has Arrived: A Study of Firmware Update VulnerabilitiesYuhao Wu, Jinwen Wang, Yujie Wang, Shixuan Zhai et al.USENIX Security 2024 · 33 citations
- ChainReactor: Automated Privilege Escalation Chain Discovery via AI PlanningGiulio De Pasquale, Ilya Grishchenko, Riccardo Iesari, Gabriel Pizarro et al.USENIX Security 2024 · 15 citations
- Adding Spatial Memory Safety to EDK II through Checked C (Experience Paper)Sourag Cherupattamoolayil, Arunkumar Bhattar, Connor Glosner, Aravind MachiryISSTA 2025
- FUZZUER: Enabling Fuzzing of UEFI Interfaces on EDK-2Connor Glosner, Aravind MachiryNDSS 2025
- μEFI: A Microkernel-Style UEFI with Isolation and TransparencyLe Chen, Yiyang Wu, Jinyu Gu, Yubin Xia et al.USENIX ATC 2025
Related papers
- RSFuzzer: Discovering Deep SMI Handler Vulnerabilities in UEFI Firmware with Hybrid FuzzingJiawei Yin, Menghao Li, Yuekang Li, Yong Yu et al.S&P 2023
- SmuFuzz: Enable Deep System Management Mode Fuzzing in Fully Featured UEFI Runtime EnvironmentJianqiang Wang, Yi Xiang, Meng Wang, Qinying Wang et al.S&P 2026
- UEFI Firmware Fuzzing with Simics Virtual PlatformZhenkun Yang, Yuriy Viktorov, Jin Yang, Jiewen Yao et al.DAC 2020 · 8 citations
- STASE: Static Analysis Guided Symbolic Execution for UEFI Vulnerability Signature GenerationMd Shafiuzzaman, Achintya Desai, Laboni Sarker, Tevfik BultanASE 2024 · 1 citation
- Through the Authentication Maze: Detecting Authentication Bypass Vulnerabilities in Firmware BinariesNanyu Zhong, Yuekang Li, Yanyan Zou, Jiaxu Zhao et al.NDSS 2026
