FuzzUEr: UEFI Firmware Fuzzer
A fuzzing framework for UEFI firmware interfaces on EDK-2, with firmware-adapted sanitizers, discovering 20 zero-day vulnerabilities. Published at NDSS 2025.
A fuzzing framework for UEFI firmware interfaces on EDK-2, with firmware-adapted sanitizers, discovering 20 zero-day vulnerabilities. Published at NDSS 2025.
Compiler-based vulnerability prevention for firmware: extending 3C to bring automated spatial memory safety to EDK II. Published at ISSTA 2025.
Collaborative research on Linux/Android kernel vulnerability analysis, exploit adaptation, and crash reproduction.
Published in Network and Distributed System Security Symposium (NDSS 2025), 2025
FuzzUEr is a novel fuzzing framework for testing UEFI firmware interfaces on EDK-2, which discovered 20 zero-day security vulnerabilities in the latest version of EDK-II.
Recommended citation: Connor Glosner, Aravind Machiry. "FuzzUEr: Enabling Fuzzing of UEFI Interfaces on EDK-2." NDSS 2025. https://cglosner.github.io/files/FuzzUEr__Enabling_Fuzzing_of_UEFI_Interfaces__on__EDK2.pdf
Published in ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA 2025), 2025
This paper presents our experience adding spatial memory safety guarantees to the UEFI firmware reference implementation (EDK II) using Checked C, a backward-compatible extension of C with bounds-checked pointer types.
Recommended citation: Sourag Cherupattamoolayil, Arunkumar Bhattar, Connor Glosner, Aravind Machiry. "Adding Spatial Memory Safety to EDK II through Checked C (Experience Paper)." ISSTA 2025. https://cglosner.github.io/files/Converting_EDK_II_to_Checked_C_with_3C.pdf
Published:
Presented our work on FuzzUEr, a novel fuzzing framework for testing UEFI firmware interfaces on EDK-2. This work discovered 20 zero-day security vulnerabilities in the latest version of EDK-II.