Author Topic: WPBT aka Windows Platform Binary Table  (Read 3955 times)

jj2007

  • Member
  • *****
  • Posts: 13300
  • Assembly is fun ;-)
    • MasmBasic
WPBT aka Windows Platform Binary Table
« on: August 13, 2015, 09:31:44 PM »
http://firmwaresecurity.com/2015/08/11/lenovo-lse-wpbt-and-wpbbin-exe/
Quote
A rich set of tools exist to aid Windows provisioning, ranging from driver injection and offline registry management to sysprep imaging tools.  However, there is a small set of software where the tools are not enough.  The software is absolutely critical for the execution of Windows but for one reason or another, the vendor is unable to distribute the software to every provisioning entity.  This paper describes a mechanism for a platform, via the boot firmware, to publish a binary to Windows for execution.  The mechanism leverages a boot firmware component to publish a binary in physical memory described to Windows using a fixed ACPI table

Lovely 8)


MichaelW

  • Global Moderator
  • Member
  • *****
  • Posts: 1196
Re: WPBT aka Windows Platform Binary Table
« Reply #2 on: August 14, 2015, 05:52:30 PM »
From Lenovo Security Advisory: LEN-2015-020, here:

Quote
Lenovo’s use of LSE was not consistent with these guidelines and Lenovo recommends customers disable this utility by running a disabler program that disables LSE and removes the LSE files from the system.

Hopefully it won't do a Sony BMG "fix".
Well Microsoft, here’s another nice mess you’ve gotten us into.