CVE-2024-0762: Potential buffer overflow when handling UEFI variables
Potential buffer overflow in unsafe UEFI variable handling
in Phoenix SecureCore™ for select Intel platforms
This issue affects:
Phoenix
SecureCore™ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998;
Phoenix
SecureCore™ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562;
Phoenix
SecureCore™ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323;
Phoenix
SecureCore™ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287;
Phoenix
SecureCore™ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236;
Phoenix
SecureCore™ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184;
Phoenix
SecureCore™ for Intel Alder Lake: from 4.4.0.1 before 4.4.0.269;
Phoenix
SecureCore™ for Intel Raptor Lake: from 4.5.0.1 before 4.5.0.218;
Phoenix
SecureCore™ for Intel Meteor Lake: from 4.5.1.1 before 4.5.1.15.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0762?
CVE-2024-0762 is classified as a potential buffer overflow vulnerability that could have significant security implications.
How do I fix CVE-2024-0762?
To remediate CVE-2024-0762, it is advised to update the Phoenix SecureCore firmware to the latest version that addresses this vulnerability.
Which systems are affected by CVE-2024-0762?
CVE-2024-0762 affects select Intel platforms running Phoenix SecureCore firmware, specifically models using Intel Kaby Lake and Coffee Lake chipsets.
What are the risks associated with CVE-2024-0762?
The risks associated with CVE-2024-0762 include potential unauthorized access, system instability, and risk of malware exploitation.
Has CVE-2024-0762 been publicly disclosed?
Yes, CVE-2024-0762 has been publicly disclosed and is being actively monitored by the cybersecurity community.