AI Vulnerability Finding
微软的AI系统发现了GRUB2和U-Boot等系统中的多个漏洞,包括缓冲区溢出和侧信道攻击等。这些漏洞可能被用于绕过UEFI安全启动保护并执行任意代码。尽管当前难以直接利用,但AI在漏洞发现方面的表现令人印象深刻。 2025-4-11 11:4:47 Author: www.schneier.com(查看原文) 阅读量:4 收藏

Microsoft is reporting that its AI systems are able to find new vulnerabilities in source code:

Microsoft discovered eleven vulnerabilities in GRUB2, including integer and buffer overflows in filesystem parsers, command flaws, and a side-channel in cryptographic comparison.

Additionally, 9 buffer overflows in parsing SquashFS, EXT4, CramFS, JFFS2, and symlinks were discovered in U-Boot and Barebox, which require physical access to exploit.

The newly discovered flaws impact devices relying on UEFI Secure Boot, and if the right conditions are met, attackers can bypass security protections to execute arbitrary code on the device.

Nothing major here. These aren’t exploitable out of the box. But that an AI system can do this at all is impressive, and I expect their capabilities to continue to improve.

Tags: , ,

Posted on April 11, 2025 at 7:04 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/04/ai-vulnerability-finding.html
如有侵权请联系:admin#unsafe.sh