logo

Phoenix UEFI flaw puts long list of Intel chips in hot seat

ID: d5cb59cc-85e0-5ae6-a0e8-08422d02a718

STIX ID: report--d5cb59cc-85e0-5ae6-a0e8-08422d02a718

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-06-21

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Eclypsium disclosed CVE-2024-0762, a high-severity (CVSSv3 7.5) buffer overflow in Phoenix SecureCore UEFI's handling of the TCG2_CONFIGURATION TPM variable that can enable privilege escalation and persistent UEFI-level code execution across many Intel processor families; vendors including Lenovo have issued firmware updates and Phoenix provided mitigations, and no public proof-of-concept or confirmed in-the-wild exploitation was released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.