Solved Gigabyte Download Assistant Vulnerabilities Reported by Eclypsium Research


thecaretaker

Well-known member
Member
VIP
Local time
9:26 PM
Posts
168
Location
1066 Country, UK
OS
Windows 11 Pro Version 23H2 OS Build 22631.3374
I see Gigabyte are rushing to fix a vulnerability in its BIOS for motherboard that use the App Center. By default, when you start your PC you get a pop up (notification) asking you to download the App Center. This behaviour can be turned off in the BIOS. I personally don't need or want any of the extra items that are controlled by the App Center and have turned this off in the BIOS.

What I don't know, is if by turning this behaviour off in the BIOS, does that render my PC safe from this vulnerability or do I still need to update the BIOS which was released today: BIOS Update

This is the information released yesterday by Eclypsium: Risk-from-gigabyte-app-center-backdoor
 

My Computer

System One

  • OS
    Windows 11 Pro Version 23H2 OS Build 22631.3374
    Computer type
    PC/Desktop
    Manufacturer/Model
    Local shop built (KC Computers Ltd)
    CPU
    Intel Core i9 13900F
    Motherboard
    Gigabyte Z690 Gaming X (rev. 1.0/1.1) - (BIOS: F29 Dec 22, 2023)
    Memory
    2 x Kingston Fury 32gb DDR5 5600 Beast
    Graphics Card(s)
    Gigabyte Eagle (Nvidia) RTX 3060
    Sound Card
    Chord Async USB 44.1kHz - 384kHz 2Qute DAC
    Monitor(s) Displays
    piXL PX27UDH4K 27 Inch Frameless IPS Monitor
    Screen Resolution
    4K (3840 x 2160) 60fps
    Hard Drives
    1 x KINGSTON NVMe M.2 SSDSKC3000D2048G 2TB
    1 x Samsung SSD 870 EVO 250GB
    2 x Crucial CT4000MX500SSD1 4TB
    2 x Crucial CT2000MX500SSD1 2TB
    1 x Crucial CT250MX500SSD1 250.0 GB
    PSU
    Gigabyte 750w
    Case
    Fractal Torrent
    Cooling
    Stock Intel CPU, 2 x Fractal 180mm PWM (front), 3 x Fractal 140mm PWM (bottom)
    Keyboard
    Logitech MX Mechanical Wireless Illuminated Performance Keyboard
    Mouse
    Logitech MX Master 3S Wireless Performance Mouse
    Internet Speed
    960 Mbps/330 Mbps Trooli FTTP
    Browser
    Firefox
    Antivirus
    Eset Nod32
I see Gigabyte are rushing to fix a vulnerability in its BIOS for motherboard that use the App Center. By default, when you start your PC you get a pop up (notification) asking you to download the App Center. This behaviour can be turned off in the BIOS. I personally don't need or want any of the extra items that are controlled by the App Center and have turned this off in the BIOS.

What I don't know, is if by turning this behaviour off in the BIOS, does that render my PC safe from this vulnerability or do I still need to update the BIOS which was released today: BIOS Update

This is the information released yesterday by Eclypsium: Risk-from-gigabyte-app-center-backdoor


Try to keep the motherboard chipset drivers, up to date.
As for the BIOS... try to only update (flash), the BIOS when necessary.

Due to Windows 11's never ending changes... you should probably flash the BIOS only every 3-4 versions.
On all other Windows versions, you should only flash the BIOS when absolutely needed.

Motherboard utility software... worse than vampires, werewolves, and giant Japanese robot warriors.
 
Last edited:

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦22631.3447 ♦♦♦♦♦♦♦23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 4702)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Internet Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Mouse
    Logitech Optical M-BT96a
    Keyboard
    Logitech Classic Keybooard 200
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 13 years?
Try to keep the motherboard chipset drivers, up to date.
As for the BIOS... try to only update (flash), the BIOS when necessary.

Dues to Windows 11's never ending changes... you should probably flash the BIOS only every 3-4 versions.
On all other Windows versions, you should only flash the BIOS when absolutely needed.

Motherboard utility software... worse than vampires, werewolves, and giant Japanese robot warriors.
Thanks for the advice Ghot. I would like to add, Motherboard Utility Software... Is as much use as a fart in a spacesuit :giggle:
 

My Computer

System One

  • OS
    Windows 11 Pro Version 23H2 OS Build 22631.3374
    Computer type
    PC/Desktop
    Manufacturer/Model
    Local shop built (KC Computers Ltd)
    CPU
    Intel Core i9 13900F
    Motherboard
    Gigabyte Z690 Gaming X (rev. 1.0/1.1) - (BIOS: F29 Dec 22, 2023)
    Memory
    2 x Kingston Fury 32gb DDR5 5600 Beast
    Graphics Card(s)
    Gigabyte Eagle (Nvidia) RTX 3060
    Sound Card
    Chord Async USB 44.1kHz - 384kHz 2Qute DAC
    Monitor(s) Displays
    piXL PX27UDH4K 27 Inch Frameless IPS Monitor
    Screen Resolution
    4K (3840 x 2160) 60fps
    Hard Drives
    1 x KINGSTON NVMe M.2 SSDSKC3000D2048G 2TB
    1 x Samsung SSD 870 EVO 250GB
    2 x Crucial CT4000MX500SSD1 4TB
    2 x Crucial CT2000MX500SSD1 2TB
    1 x Crucial CT250MX500SSD1 250.0 GB
    PSU
    Gigabyte 750w
    Case
    Fractal Torrent
    Cooling
    Stock Intel CPU, 2 x Fractal 180mm PWM (front), 3 x Fractal 140mm PWM (bottom)
    Keyboard
    Logitech MX Mechanical Wireless Illuminated Performance Keyboard
    Mouse
    Logitech MX Master 3S Wireless Performance Mouse
    Internet Speed
    960 Mbps/330 Mbps Trooli FTTP
    Browser
    Firefox
    Antivirus
    Eset Nod32
Is as much use as a fart in a spacesuit



As much use as...

a screen door in a submarine.
a pay toilet in a diarrhea ward.
a chocolate teapot.
an ashtray on a motorcycle.
an inflatable dart board.
a solar powered foghorn.
a water proof teabag.
an ejector seat in a helicopter.
 
Last edited:

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦22631.3447 ♦♦♦♦♦♦♦23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 4702)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Internet Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Mouse
    Logitech Optical M-BT96a
    Keyboard
    Logitech Classic Keybooard 200
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 13 years?
I see Brink has just posted about it: HERE
 

My Computer

System One

  • OS
    Windows 11 Pro Version 23H2 OS Build 22631.3374
    Computer type
    PC/Desktop
    Manufacturer/Model
    Local shop built (KC Computers Ltd)
    CPU
    Intel Core i9 13900F
    Motherboard
    Gigabyte Z690 Gaming X (rev. 1.0/1.1) - (BIOS: F29 Dec 22, 2023)
    Memory
    2 x Kingston Fury 32gb DDR5 5600 Beast
    Graphics Card(s)
    Gigabyte Eagle (Nvidia) RTX 3060
    Sound Card
    Chord Async USB 44.1kHz - 384kHz 2Qute DAC
    Monitor(s) Displays
    piXL PX27UDH4K 27 Inch Frameless IPS Monitor
    Screen Resolution
    4K (3840 x 2160) 60fps
    Hard Drives
    1 x KINGSTON NVMe M.2 SSDSKC3000D2048G 2TB
    1 x Samsung SSD 870 EVO 250GB
    2 x Crucial CT4000MX500SSD1 4TB
    2 x Crucial CT2000MX500SSD1 2TB
    1 x Crucial CT250MX500SSD1 250.0 GB
    PSU
    Gigabyte 750w
    Case
    Fractal Torrent
    Cooling
    Stock Intel CPU, 2 x Fractal 180mm PWM (front), 3 x Fractal 140mm PWM (bottom)
    Keyboard
    Logitech MX Mechanical Wireless Illuminated Performance Keyboard
    Mouse
    Logitech MX Master 3S Wireless Performance Mouse
    Internet Speed
    960 Mbps/330 Mbps Trooli FTTP
    Browser
    Firefox
    Antivirus
    Eset Nod32
To answer your question, in this particular case, if this bios is Gibabytes's fix for the back door issue Brink mentioned, this new bios DOES definitely need to be flashed. You would need to read the release notes on the update to verify that is the fact.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3447
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
To answer your question, in this particular case, if this bios is Gibabytes's fix for the back door issue Brink mentioned, this new bios DOES definitely need to be flashed. You would need to read the release notes on the update to verify that is the fact.
Yes, I have updated the bios on this occasion. I had a few TPM mismatch errors when I had fast boot set, but turned hibernate off and back on and it cleared it. All seems well now.
 

Attachments

  • Screenshot 2023-06-01 200339.png
    Screenshot 2023-06-01 200339.png
    38.3 KB · Views: 1

My Computer

System One

  • OS
    Windows 11 Pro Version 23H2 OS Build 22631.3374
    Computer type
    PC/Desktop
    Manufacturer/Model
    Local shop built (KC Computers Ltd)
    CPU
    Intel Core i9 13900F
    Motherboard
    Gigabyte Z690 Gaming X (rev. 1.0/1.1) - (BIOS: F29 Dec 22, 2023)
    Memory
    2 x Kingston Fury 32gb DDR5 5600 Beast
    Graphics Card(s)
    Gigabyte Eagle (Nvidia) RTX 3060
    Sound Card
    Chord Async USB 44.1kHz - 384kHz 2Qute DAC
    Monitor(s) Displays
    piXL PX27UDH4K 27 Inch Frameless IPS Monitor
    Screen Resolution
    4K (3840 x 2160) 60fps
    Hard Drives
    1 x KINGSTON NVMe M.2 SSDSKC3000D2048G 2TB
    1 x Samsung SSD 870 EVO 250GB
    2 x Crucial CT4000MX500SSD1 4TB
    2 x Crucial CT2000MX500SSD1 2TB
    1 x Crucial CT250MX500SSD1 250.0 GB
    PSU
    Gigabyte 750w
    Case
    Fractal Torrent
    Cooling
    Stock Intel CPU, 2 x Fractal 180mm PWM (front), 3 x Fractal 140mm PWM (bottom)
    Keyboard
    Logitech MX Mechanical Wireless Illuminated Performance Keyboard
    Mouse
    Logitech MX Master 3S Wireless Performance Mouse
    Internet Speed
    960 Mbps/330 Mbps Trooli FTTP
    Browser
    Firefox
    Antivirus
    Eset Nod32
Just flashed my B66M GAMING DDR4 (rev.1.0) since the same note was present with this new a-version bios. Just to be on the safe side.
 

Attachments

  • 2023-06-01 230405.jpg
    2023-06-01 230405.jpg
    34.4 KB · Views: 1

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home built
    CPU
    Intel Core i5 12400F
    Motherboard
    Gigabyte B660M GAMING DDR4 (ver. 1.0)
    Memory
    32 GB (2X16) Kingston DDR4-32 (1600 MHz)
    Graphics Card(s)
    ASUS nVidia GTX 980 TI 6 GB DDR5
    Hard Drives
    Kingston KC3000 1024 GB M.2 NVMe
    WD WDS100T2BC 1000 GB M.2 NVMe
    Internet Speed
    DL: 250 mbit/s UL: 100 mbit/s
Just flashed my B66M GAMING DDR4 (rev.1.0) since the same note was present with this new a-version bios. Just to be on the safe side.
How can one make sure that their PC have not already been infected with some low-level rootkit/malware because of this open door? I'm thinking about other PC's in the network, mice/keyboard firmware etc.
 

My Computer

System One

  • OS
    Windows 11
How can one make sure that their PC have not already been infected with some low-level rootkit/malware because of this open door? I'm thinking about other PC's in the network, mice/keyboard firmware etc.
Scan with anti-virus and/or anti-malware program. The important thing is to close the backdoor in the UEFI/BIOS that otherwise would let the bad actors right in again.
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home built
    CPU
    Intel Core i5 12400F
    Motherboard
    Gigabyte B660M GAMING DDR4 (ver. 1.0)
    Memory
    32 GB (2X16) Kingston DDR4-32 (1600 MHz)
    Graphics Card(s)
    ASUS nVidia GTX 980 TI 6 GB DDR5
    Hard Drives
    Kingston KC3000 1024 GB M.2 NVMe
    WD WDS100T2BC 1000 GB M.2 NVMe
    Internet Speed
    DL: 250 mbit/s UL: 100 mbit/s
Scan with anti-virus and/or anti-malware program. The important thing is to close the backdoor in the UEFI/BIOS that otherwise would let the bad actors right in again.
Sure, but the problem with low level UEFI firmware like this is that the OS have no idea if it’s running malicious code or not. It can lay dormant and download malware in small pieces over time to gain access to and hide from higher levels of the system. Which means that if you have been infected it’s almost impossible to get rid of. And gigabyte left the door open for this to happen.
 

My Computer

System One

  • OS
    Windows 11
Sure, but the problem with low level UEFI firmware like this is that the OS have no idea if it’s running malicious code or not. It can lay dormant and download malware in small pieces over time to gain access to and hide from higher levels of the system. Which means that if you have been infected it’s almost impossible to get rid of. And gigabyte left the door open for this to happen.
You do not understand what I am saying. After the UEFI/BIOS is flashed there is no way in for malicious code and so the backdoor is closed. After this you can start getting rid of the malicious programs in a normal way, they are not more dormant or invisible than other malware.
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home built
    CPU
    Intel Core i5 12400F
    Motherboard
    Gigabyte B660M GAMING DDR4 (ver. 1.0)
    Memory
    32 GB (2X16) Kingston DDR4-32 (1600 MHz)
    Graphics Card(s)
    ASUS nVidia GTX 980 TI 6 GB DDR5
    Hard Drives
    Kingston KC3000 1024 GB M.2 NVMe
    WD WDS100T2BC 1000 GB M.2 NVMe
    Internet Speed
    DL: 250 mbit/s UL: 100 mbit/s
You do not understand what I am saying. After the UEFI/BIOS is flashed there is no way in for malicious code and so the backdoor is closed. After this you can start getting rid of the malicious programs in a normal way, they are not more dormant or invisible than other malware.
How would one go about fixing already infected UEFI firmware? Sure, the backdoor is now closed, but what about any potential UEFI malware that was installed during the backdoor was open?
 

My Computer

System One

  • OS
    Windows 11
How would one go about fixing already infected UEFI firmware? Sure, the backdoor is now closed, but what about any potential UEFI malware that was installed during the backdoor was open?

As far as i know updating the Bios will overwrite every part of the old Bios with the new version.

This means anything that should not be there will be gone after an update.
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 10 Pro [Build 19045.4291]
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte
    CPU
    AMD Ryzen 9 5950X (4900 Mhz)
    Motherboard
    Gigabyte X570S Aorus Master
    Memory
    Corsair Dominator Platinum RGB 64 GB DDR4 3600 Mhz
    Graphics Card(s)
    nVidia GeForce RTX 4080 Founders Edition
    Sound Card
    Creative Sound Blaster AE-7
    Monitor(s) Displays
    Samsung 46" TV
    Screen Resolution
    1920x1080@60Hz
    Hard Drives
    Samsung 990 PRO NVMe SSD 4000 GB (OS/Games)
    Samsung 860 EVO SSD 2000 GB (Games)
    Samsung 860 EVO SSD 4000 GB (Games)
    PSU
    Corsair AX1500i (1500W)
    Case
    Phanteks Enthoo Luxe (Black)
    Cooling
    Corsair H150i PRO RGB
    Keyboard
    Logitech G910 Orion Spectrum RGB
    Mouse
    Logitech MX518 Legendary 16000 DPI
    Internet Speed
    Fiber 1000/1000 Mbit
    Browser
    Google Chrome
    Antivirus
    Malwarebytes Premium 4.6.12
    Other Info
    Intel Wi-Fi 6E AX210 (M.2 Add-in Card)
  • Operating System
    Windows 11 Pro [Build 26100.1]
    Computer type
    PC/Desktop
    Manufacturer/Model
    Evga
    CPU
    Intel Xeon W3690 (3733Mhz)
    Motherboard
    Evga X58 Classified (E760)
    Memory
    Corsair Dominator Platinum 24GB DDR3 (1600 Mhz)
    Graphics card(s)
    Evga Titan X Hybrid SuperClocked (Maxwell)
    Sound Card
    Realtek HD Audio (ALC 892)
    Monitor(s) Displays
    Samsung 24" SyncMaster 2493HM
    Screen Resolution
    1920x1200@60Hz
    Hard Drives
    Samsung 950 PRO NVMe 512 GB (OS/Games)
    4x Seagate Barracuda ES3 2000 GB (Storage)
    PSU
    Corsair AX850 (850W)
    Case
    NZXT Phantom 820 (White)
    Cooling
    Corsair H100
    Mouse
    Logitech G400S
    Keyboard
    Logitech G19S
    Internet Speed
    Fiber 1000/1000 Mbit
    Browser
    Google Chrome
    Antivirus
    Malwarebytes Premium 4.6.12
    Other Info
    Intel Wi-Fi 6 AX200 (PCIe Add-in Card / HP 6VF53AA)
    Asus USB 3.1 2x Type-A 10Gbps (PCIe Add-in Card)
Back
Top Bottom