HomeSecurityPhoenix UEFI vulnerability affects hundreds of Intel computer models

Phoenix UEFI vulnerability affects hundreds of Intel computer models

A recently discovered vulnerability in the Phoenix SecureCore UEFI , tracked as CVE-2024-0762, affects devices with many Intel processors, with Lenovo already releasing new firmware updates to resolve the flaw.

See also: Intel Thunderbolt Share: Sharing two PCs with just one USB

Phoenix UEFI vulnerability

The vulnerability, called “UEFICANHAZBUFFEROVERFLOW“, is a buffer overflow in the firmware’s Trusted Platform Module (TPM) configuration, which could be exploited to execute code on vulnerable devices.

The flaw was discovered by Eclypsium , who spotted it on Lenovo ThinkPad X1 Carbon 7th Gen and X1 Yoga 4th Gen devices , but later confirmed with Phoenix that it affects SecureCore firmware for Alder Lake, Coffee Lake, Comet Lake, Ice Lake, Jasper Lake, and Intel Kaby Lake, Meteor Lake, Raptor Lake, Rocket Lake , and Tiger Lake processors .

Due to the large number of Intel processors using this firmware, the vulnerability has the potential to affect hundreds of models from Lenovo, Dell, Acer , and HP.

Phoenix UEFI vulnerability is a valuable target

UEFI firmware is considered more secure as it includes Secure Boot, which is supported by all modern operating systems, including Windows, macOS , and Linux. Secure Boot cryptographically confirms that a device is booting only with trusted drivers and software, blocking the boot process if it detects malware.

As Secure Boot makes it much more difficult for malicious actors to install persistent boot malware and drivers, UEFI bugs are becoming increasingly popular for creating malware called bootkits.

See also: Intel and Lenovo servers affected by 6-year-old BMC flaw

Bootkits are malware that loads very early in the UEFI boot process, giving malicious programs low-level access to the operating system and making them very difficult to detect, such as the BlackLotus, CosmicStrand , and MosaicAggressor UEFI.

Phoenix SecureCore

Eclypsium says the vulnerability they found lies in a buffer overflow within the System Management Mode (SMM) of the Phoenix UEFI firmware, allowing attackers to potentially overwrite adjacent memory.

If the memory had been overwritten with the correct data, an attacker could potentially escalate privileges and gain code execution capabilities in the firmware to install bootkit malware.

After discovering the bug, Eclypsium coordinated a disclosure with Phoenix and Lenovo to fix the flaws.

In April, Phoenix issued an advisory, and Lenovo began rolling out new firmware in May to address the vulnerabilities on more than 150 different models. It's important to note that not all models have firmware available right now, with many scheduled for later this year.

See also: Intel: 40 TOPS NPU the Minimum Requirement for Copilot & AI PCs

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A security vulnerability, such as the one in Phoenix UEFI, is a flaw or weakness in a system, network, or application that a threat actor could exploit to gain unauthorized access to data, disrupt operations, or cause other forms of harm. These vulnerabilities can arise from a variety of sources, including software bugs, misconfigurations, or even human error. Identifying and addressing security vulnerabilities is critical to maintaining the integrity, confidentiality, and availability of information and resources. Regular security assessments, timely patching , and adherence to best practices are essential measures to mitigate the risks associated with security vulnerabilities.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS