Critical “PixieFail” Flaws Expose Millions of Devices to Cyberattacks
ID: 9de44587-f997-56b5-8ada-109690aa5b93
STIX ID: report--9de44587-f997-56b5-8ada-109690aa5b93
Feed Name: HackRead
Threat Score
**PixieFAIL — Nine EDK II UEFI network-stack vulnerabilities:** Quarkslab discovered nine vulnerabilities in the TianoCore EDK II NetworkPkg used for PXE/network boot that enable pre-boot remote code execution, DNS/DHCP poisoning, info leakage, and DoS across IPv4/IPv6; CVEs and CVSS scores are provided, proof-of-concept code was released for multiple issues, and vendors (AMI, Intel, Insyde, Phoenix) were notified with patches published and a firmware update released on 2024-01-16.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
