ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Intel-powered computers affected by serious firmware flaw (CVE-2024-0762)

highVulnerability exploited in the wildimportance 60CVE-2024-0762

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0762
Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for select Intel platforms This issue affects:

Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for select Intel platforms This issue affects: Phoenix SecureCore™ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998; Phoenix SecureCore™ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562; Phoenix SecureCore™ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323; Phoenix SecureCore™ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287; Phoenix SecureCore™ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236; Phoenix SecureCore™ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184; Phoenix SecureCore™ for Intel Alder Lake: from 4.4.0.1 before 4.4.0.269; Phoenix SecureCore™ for Intel Raptor Lake: from 4.5.0.1 before 4.5.0.218; Phoenix SecureCore™ for Intel Meteor Lake: from 4.5.1.1 before 4.5.1.15.

NVD description · AI analysis pending
7.8<1% PoC
  • phoenixtech securecore technology
Full article319 words · extracted from helpnetsecurity.com · click to collapse

A vulnerability (CVE-2024-0762) in the Phoenix SecureCore UEFI, which runs on various Intel processors, could be exploited locally to escalate privileges and run arbitrary code within the firmware during runtime.

CVE-2024-0762

“This type of low-level exploitation is typical of firmware backdoors (e.g., BlackLotus) that are increasingly observed in the wild,” Eclypsium researchers noted.

“Such implants give attackers ongoing persistence within a device and often, the ability to evade higher-level security measures running in the operating system and software layers.”

About CVE-2024-0762

The vulnerability is related to an unsafe call to the GetVariable UEFI service, which could lead to an exploitable stack buffer overflow condition.

“To be clear, this vulnerability lies in the UEFI code handling [Trusted Platform Module] configuration—in other words, it doesn’t matter if you have a security chip like a TPM if the underlying code is flawed,” the researchers noted.

The vulnerability was discovered on two Lenovo ThinkPad laptops but Phoenix Technologies has confirmed that it affects multiple versions of its SecureCore firmware, running on various Intel processor families: Alder Lake, Coffee Lake, Comet Lake, Ice Lake, Jasper Lake, Kaby Lake, Meteor Lake, Raptor Lake, Rocket Lake, and Tiger Lake. You can be sure that Lenovo’s laptops are not the only vulnerable computers our there.

Phoenix has implemented mitigations in its UEFI earlier this year, and Lenovo has pushed out BIOS updates for its affected devices. Other vendors are sure to follow in their footsteps – if they haven’t already. Users are advised to check vendor websites for the latest firmware updates.

There is currently no mention of in-the-wild exploitation. In truth, widespread exploitation exploitation may be difficult. “The possibility of exploitation depends on the configuration and permission assigned to the TCG2_CONFIGURATION variable, which could be different for every platform,” according to the researchers.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/06/21/cve-2024-0762/