A critical vulnerability has been identified in the UEFI firmware of several major motherboard brands, including ASRock, ASUS, MSI, and Gigabyte, which allows attackers to exploit the system during the early boot process via PCIe-connected DMA devices. This flaw enables malicious actors to bypass operating system security controls by taking advantage of the Input-Output Memory Management Unit (IOMMU) not fully initializing upon boot, leaving system RAM exposed to unauthorized access and manipulation.
The vulnerability has significant implications for both general system security and the integrity of anti-cheat mechanisms in online games. Riot Games, the developer of Valorant, has responded by blocking players who do not update their BIOS with the latest security patches, as the flaw allows sophisticated cheating devices to evade detection by anti-cheat software. Major motherboard vendors have released security updates to address the issue, and users are strongly advised to apply these patches to mitigate the risk of exploitation.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Riot Games updated its Vanguard anti-cheat protections so vulnerable systems without the required BIOS fixes could be blocked from launching Valorant or restricted from competitive play. Riot said enforcement would focus on systems associated with cheating risk rather than all players universally.
ASRock, ASUS, Gigabyte, and MSI acknowledged the issue and began publishing BIOS or firmware updates to correct early IOMMU initialization. Vendor and CERT advisories urged users and administrators to apply the patches promptly, especially where physical access cannot be tightly controlled.
The vulnerability was coordinated with CERT/CC and CERT Taiwan, and multiple CVEs were assigned: CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304. Advisories highlighted that firmware could falsely report DMA protection as enabled while systems remained exposed before the OS loaded.
Nick Peterson and Mohamed Al-Sharifi of Riot Games identified a UEFI flaw affecting certain ASRock, ASUS, Gigabyte, and MSI motherboards. The bug leaves the IOMMU improperly initialized during early boot, enabling pre-boot DMA attacks via malicious PCIe devices with physical access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcearstechnica.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcesecurityonline.info
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.