Potential buffer overflow in unsafe UEFI variable handling (CVE-2024-0762) #shorts #breaking

CVE

This CVE relates to a potential buffer overflow in unsafe UEFI variable handling, which surfaced just this month. Although not classified as a zero-day, this vulnerability affects multiple versions of Phoenix: SecureCore™ firmware specifically designed for various Intel processor families ranging from Kaby Lake to upcoming Meteor Lake. Exploiting this flaw could allow attackers to perform local privilege escalation and execute arbitrary code on affected systems. Users of Intel-powered computers running these specific firmware versions should take note of this vulnerability.

Watch the full video on YouTube: CVE-2024-0762

Remediation and exploitation details

This chain involves the following actors

This following systems are involved

Attack entry point

Remediation actions

Exploitation actions

Related Content

NOTE: The following related content has not been vetted and may be unsafe.

CVE database technical details

CVE ID
CVE-2024-0762
Description
Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for select Intel platforms This issue affects: Phoenix SecureCore™ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998; Phoenix SecureCore™ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562; Phoenix SecureCore™ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323; Phoenix SecureCore™ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287; Phoenix SecureCore™ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236; Phoenix SecureCore™ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184; Phoenix SecureCore™ for Intel Alder Lake: from 4.4.0.1 before 4.4.0.269; Phoenix SecureCore™ for Intel Raptor Lake: from 4.5.0.1 before 4.5.0.218; Phoenix SecureCore™ for Intel Meteor Lake: from 4.5.1.1 before 4.5.1.15.
Provider
Phoenix
CWE / problem types
Affected Software Versions
Phoenix:SecureCore™ for Intel Kaby Lake:[{'lessThan': '4.0.1.998', 'status': 'affected', 'version': '4.0.1.1', 'versionType': 'custom'}],Phoenix:SecureCore™ for Intel Coffee Lake:[{'lessThan': '4.1.0.562', 'status': 'affected', 'version': '4.1.0.1', 'versionType': 'custom'}],Phoenix:SecureCore™ for Intel Ice Lake:[{'lessThan': '4.2.0.323', 'status': 'affected', 'version': '4.2.0.1', 'versionType': 'custom'}],Phoenix:SecureCore™ for Intel Comet Lake:[{'lessThan': '4.2.1.287', 'status': 'affected', 'version': '4.2.1.1', 'versionType': 'custom'}],Phoenix:SecureCore™ for Intel Tiger Lake:[{'lessThan': '4.3.0.236', 'status': 'affected', 'version': '4.3.0.1', 'versionType': 'custom'}],Phoenix:SecureCore™ for Intel Jasper Lake:[{'lessThan': '4.3.1.184', 'status': 'affected', 'version': '4.3.1.1', 'versionType': 'custom'}],Phoenix:SecureCore™ for Intel Alder Lake:[{'lessThan': '4.4.0.269', 'status': 'affected', 'version': '4.4.0.1', 'versionType': 'custom'}],Phoenix:SecureCore™ for Intel Raptor Lake:[{'lessThan': '4.5.0.218', 'status': 'affected', 'version': '4.5.0.1', 'versionType': 'custom'}],Phoenix:SecureCore™ for Intel Meteor Lake:[{'lessThan': '4.5.1.15', 'status': 'affected', 'version': '4.5.1.1', 'versionType': 'custom'}]
Date Published
2024-05-14T14:56:25.578Z
Last Updated
2025-03-20T13:37:52.909Z