logo

Phoenix UEFI vulnerability impacts hundreds of Intel PC models

ID: 763f4faa-a31e-53e3-be65-960f997d1590

STIX ID: report--763f4faa-a31e-53e3-be65-960f997d1590

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-06-20

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A buffer overflow vulnerability (CVE-2024-0762), nicknamed UEFICANHAZBUFFEROVERFLOW, was found in Phoenix SecureCore UEFI firmware affecting many Intel CPU families and potentially hundreds of OEM models; the flaw in TPM configuration handling could allow firmware-level code execution and installation of persistent bootkit malware. Eclypsium disclosed the issue and Phoenix and Lenovo have published advisories and begun releasing firmware updates, but not all affected systems have fixes available yet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.