A few bits of news to add to this:
https://firmwaresecurity.com/2016/06/29/exploiting-lenovo-firmware-part-2/
These days, it is nice to know that a firmware bug is probably an accidental defect, rather than some backdoor. 🙂
In 2015, UEFI Forum used to do Security Advisories, with 2 PDFs each containing more than a dozen potential exploits. I wonder how many of those are in today’s vendors codebases? No more advisories from UEFI Forum since 2015, so who knows what other cut-and-paste OEM/IBV bugs are being propogated? I wish UEFI Forum would issue more Security Advisories, multiple bugfixes on the EDK2-devel project appear to merit this kind of attention.