CVE-2019-18279: High severity phoenix securecore technology vulnerability
In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application to gain elevated privileges. Adverse impacts are limited to the Windows environment and there is no known direct impact to the UEFI firmware. This was fixed in late June 2019.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18279?
CVE-2019-18279 is a vulnerability in Phoenix SCT WinFlash versions 1.1.12.0 through 1.5.74.0 that allows a malicious Windows application to gain elevated privileges.
What is the severity of CVE-2019-18279?
CVE-2019-18279 has a severity rating of 8.8 (high).
How can CVE-2019-18279 be exploited?
CVE-2019-18279 can be exploited by a malicious Windows application using the included drivers in Phoenix SCT WinFlash versions 1.1.12.0 through 1.5.74.0.
Is UEFI firmware affected by CVE-2019-18279?
There is no known direct impact to the UEFI firmware from CVE-2019-18279.
Has CVE-2019-18279 been fixed?
CVE-2019-18279 was fixed in late June 2019.