Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-665 — Exploitation of Thunderbolt Protection Flaws
CAPEC-665

Exploitation of Thunderbolt Protection Flaws

TLP:CLEAR

Description

Typical severity: Very High. Likelihood of attack: Low. An adversary leverages a firmware weakness within the Thunderbolt protocol, on a computing device to manipulate Thunderbolt controller firmware in order to exploit vulnerabilities in the implementation of authorization and verification schemes within Thunderbolt protection mechanisms. Upon gaining physical access to a target device, the adversary conducts high-level firmware manipulation of the victim Thunderbolt controller SPI (Serial Peripheral Interface) flash, through the use of a SPI Programing device and an external Thunderbolt device, typically as the target device is booting up. If successful, this allows the adversary to modify memory, subvert authentication mechanisms, spoof identities and content, and extract data and memory from the target device. Currently 7 major vulnerabilities exist within Thunderbolt protocol with 9 attack vectors as noted in the Execution Flow.

Mitigation

Implementation: Kernel Direct Memory Access Protection | Configuration: Enable UEFI option USB Passthrough mode - Thunderbolt 3 system port operates as USB 3.1 Type C interface | Configuration: Enable UEFI option DisplayPort mode - Thunderbolt 3 system port operates as video-only DP interface | Configuration: Enable UEFI option Mixed USB/DisplayPort mode - Thunderbolt 3 system port operates as USB 3.1 Type C interface with support for DP mode | Configuration: Set Security Level to SL3 for Thunderbolt 2 system port

Details

Platforms
Communications
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.