logo

PixieFail UEFI Flaws Expose Millions of Computers to RCE, DoS, and Data Theft

ID: 31781875-335c-55b3-bd05-f4c1bd40ebfa

STIX ID: report--31781875-335c-55b3-bd05-f4c1bd40ebfa

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-01-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

PixieFail is a set of nine vulnerabilities in the TianoCore EDK II NetworkPkg (UEFI PXE network stack) that affect UEFI firmware from vendors such as AMI, Intel, Insyde, and Phoenix. The flaws—ranging from buffer overflows and out-of-bounds reads to infinite loops and a weak PRNG—can enable remote code execution, denial-of-service, DNS/DHCP poisoning, and data leakage; severity varies by CVE (several rated 8.3). Exploitability depends on firmware build and PXE configuration, and an attacker on the local network (and in some scenarios remotely) could leverage these weaknesses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.