SecurityWeek reports that ASUS, ASRock, Gigabyte, and MSI had certain motherboards impacted by a new protection mechanism failure issue associated with UEFI implementations and the Input-Output Memory Management Unit, which could be leveraged to compromise data in memory and facilitate pre-boot code injection.
Attackers looking to exploit the vulnerability, which is tracked as CVE-2025-11901, CVE-202514302, CVE-2025-14303, and CVE-2025-14304, need to establish a connection between an illicit PCI Express device and a computer with an impacted motherboard, according to an advisory from the Carnegie Mellon University's CERT/CC.
Motherboards from Intel, AMD, Supermicro, Phoenix Technologies, AMI, and Insyde were not affected by the flaw, which was discovered and reported by Riot Games researchers.
"In environments where physical access cannot be fully controlled or relied on, prompt patching and adherence to hardware security best practices are especially important. Because the IOMMU also plays a foundational role in isolation and trust delegation in virtualized and cloud environments, this flaw highlights the importance of ensuring correct firmware configuration even on systems not typically used in data centers," said CERT/CC.
Attackers looking to exploit the vulnerability, which is tracked as CVE-2025-11901, CVE-202514302, CVE-2025-14303, and CVE-2025-14304, need to establish a connection between an illicit PCI Express device and a computer with an impacted motherboard, according to an advisory from the Carnegie Mellon University's CERT/CC.
Motherboards from Intel, AMD, Supermicro, Phoenix Technologies, AMI, and Insyde were not affected by the flaw, which was discovered and reported by Riot Games researchers.
"In environments where physical access cannot be fully controlled or relied on, prompt patching and adherence to hardware security best practices are especially important. Because the IOMMU also plays a foundational role in isolation and trust delegation in virtualized and cloud environments, this flaw highlights the importance of ensuring correct firmware configuration even on systems not typically used in data centers," said CERT/CC.
