FuzzUEr: Enabling Fuzzing of UEFI Interfaces on EDK-2
Published in Network and Distributed System Security Symposium (NDSS 2025), 2025
Recommended citation: Connor Glosner, Aravind Machiry. "FuzzUEr: Enabling Fuzzing of UEFI Interfaces on EDK-2." NDSS 2025. https://cglosner.github.io/files/FuzzUEr__Enabling_Fuzzing_of_UEFI_Interfaces__on__EDK2.pdf
FuzzUEr is a novel fuzzing framework designed to test UEFI firmware interfaces on EDK-2. UEFI firmware remains difficult to analyze because of its atypical execution environment. We developed fuzzers targeting UEFI components and SMM communication paths, uncovering unsafe data flows and isolation flaws exploitable before the OS loads. This work also adapted compiler-based sanitizers (e.g., AddressSanitizer) to UEFI by introducing firmware-compatible shadow memory and custom runtime support, enabling reliable detection of memory errors during development.
Our approach resulted in the discovery of 20 zero-day security vulnerabilities in the latest version of EDK-II.
