CVE-2024-29979: Unsafe Handling of Phoenix UEFI Variables
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Manipulation.This issue affects SecureCore™ for Intel Kaby Lake: before 4.0.1.1012; SecureCore™ for Intel Coffee Lake: before 4.1.0.568; SecureCore™ for Intel Comet Lake: before 4.2.1.292; SecureCore™ for Intel Ice Lake: before 4.2.0.334.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29979?
CVE-2024-29979 is classified as a high severity vulnerability due to its potential for input data manipulation.
How do I fix CVE-2024-29979?
To remediate CVE-2024-29979, upgrade Phoenix SecureCore to versions 4.0.1.1013, 4.1.0.569, 4.2.1.293, or later releases.
Which versions of Phoenix SecureCore are affected by CVE-2024-29979?
CVE-2024-29979 impacts Phoenix SecureCore versions up to 4.2.1.292.
What type of vulnerability is CVE-2024-29979?
CVE-2024-29979 involves an improper check for unusual or exceptional conditions.
Who is impacted by CVE-2024-29979?
Entities using the affected versions of Phoenix SecureCore for Intel Kaby Lake, Coffee Lake, Comet Lake, and Ice Lake are impacted by CVE-2024-29979.