PixieFail UEFI Flaws Expose Millions of Computers to RCE, DoS, and Data Theft
ID: 31781875-335c-55b3-bd05-f4c1bd40ebfa
STIX ID: report--31781875-335c-55b3-bd05-f4c1bd40ebfa
Feed Name: The Hacker News
PixieFail is a set of nine vulnerabilities in the TianoCore EDK II NetworkPkg (UEFI PXE network stack) that affect UEFI firmware from vendors such as AMI, Intel, Insyde, and Phoenix. The flaws—ranging from buffer overflows and out-of-bounds reads to infinite loops and a weak PRNG—can enable remote code execution, denial-of-service, DNS/DHCP poisoning, and data leakage; severity varies by CVE (several rated 8.3). Exploitability depends on firmware build and PXE configuration, and an attacker on the local network (and in some scenarios remotely) could leverage these weaknesses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
