Comment by engzaanin
3 days ago
The timeout idea is interesting. If firmware can strictly bound SMM execution time, would that actually eliminate this class of attack, or just turn it into a crash/DoS instead?
3 days ago
The timeout idea is interesting. If firmware can strictly bound SMM execution time, would that actually eliminate this class of attack, or just turn it into a crash/DoS instead?
Someone would definitely notice if SMM took a long time. It would look like the core hung. The exploit is hanging another core outside SMM.