Sleeping Bouncer Vulnerability Impacts Gigabyte, MSI, ASRock, and ASUS Motherboards
## Cybersecurity: Firmware Vulnerability in Motherboards
Cybersecurity: Firmware Vulnerability in Motherboards
A significant firmware vulnerability has been identified in motherboards from manufacturers such as Gigabyte, MSI, ASRock, and ASUS. This vulnerability was discovered by Riot Games' Vanguard anti-cheat team.
The vulnerability, named "Sleeping Bouncer," allows hardware-based cheats to inject malicious code during the initial stages of system boot, bypassing existing security protections. It involves Pre-Boot DMA Protection, a feature that uses the system's Input-Output Memory Management Unit (IOMMU) to prevent unauthorized Direct Memory Access during boot.
IOMMU acts as a gatekeeper for system memory, validating device access to RAM. However, certain motherboard firmware incorrectly indicated to the operating system that Pre-Boot DMA Protection was active, while the IOMMU was not initializing correctly during early boot stages. This created a window where the system's security was compromised.
The vulnerability affects the boot sequence, particularly the privileged initialization process where firmware loads before the operating system gains control. This creates an attack vector for hardware cheats using DMA cards, bypassing CPU and Windows-level protections.
The vulnerability has broader implications for cybersecurity, potentially nullifying existing DMA detection and prevention technologies. It challenges assumptions about boot integrity, affecting security software relying on Pre-Boot DMA Protection signals. Riot Games reported this vulnerability in early 2025, leading to coordinated disclosures and BIOS updates from major vendors.
A significant firmware vulnerability has been identified in motherboards from manufacturers such as Gigabyte, MSI, ASRock, and ASUS.
ASUS : CVE-2025-11901 Gigabyte : CVE-2025-14302 MSI : CVE-2025-14303 ASRock : CVE-2025-14304
The CERT Coordination Center issued case VU#382314, documenting the vulnerability. Firmware updates have been released to ensure security features activate immediately upon system power-on.
Riot Games' Vanguard anti-cheat system will enforce stricter boot security checks. Users on vulnerable firmware versions will receive notifications requiring motherboard firmware updates to continue playing VALORANT. The company is considering mandatory security requirements for high-ranked players.
Users should update their motherboard firmware to the latest version from manufacturer websites. Security advisories and update guidance are available from ASUS, Gigabyte , MSI, and ASRock support portals. System administrators should verify Pre-Boot DMA Protection and related security features are properly configured post-update.
This discovery highlights the importance of collaboration between software developers and hardware manufacturers in addressing systemic vulnerabilities impacting the technology ecosystem.
Based on reporting by GBHackers.
