A set of nine vulnerabilities, collectively called 'PixieFail,' impact the IPv6 network protocol stack of Tianocore's EDK II, the open-source reference implementation of the UEFI specification widely used in enterprise computers and servers. The flaws are present in the PXE network boot process, which is crucial for provisioning operating systems in data centers and high-performance computing environments, and a standard procedure for loading OS images from the network at boot. The PixieFail flaws were discovered by Quarkslab researchers and have already been disclosed to impacted vendors via a coordinated effort by CERT/CC and CERT-FR. The PixieFail vulnerabilities arise from the implementation of IPv6 in the Preboot Execution Environment (PXE), part of the UEFI spec. PXE enables network booting, and its IPv6 implementation introduces additional protocols, increasing the attack surface. PixieFail attacks consist of nine flaws that can be exploited locally on a network to cause denial of service (DoS), information disclosure, remote code execution (RCE), DNS cache poisoning, and network session hijacking. Below is a summary of the nine PixieFail flaws: Of the above, the most severe are CVE-2023-45230 and CVE-2023-45235, which allow attackers to perform remote code execution, possibly leading to complete system compromise. Quarkslab has released proof-of-concept (PoC) exploits that allow admins to detect vulnerable devices on their network. The PixieFail vulnerabilities impac...
PixieFail flaws impact PXE network boot in enterprise systems
BleepingComputer
·Bill Toulas
·Published Jan 16, 2024
·Updated
Affected Software
1 affected component
Tianocore EDK II
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a set of vulnerabilities known as 'PixieFail' that affect the PXE network booting process in enterprise systems.
2
What security implications are discussed?
The vulnerabilities could allow attackers to potentially exploit the PXE network booting process to execute unauthorized code on affected systems.
3
What products or software are affected?
The primary affected software is Tianocore's EDK II, the open-source implementation of the UEFI specification.
4
How many vulnerabilities are included in the PixieFail set?
There are nine vulnerabilities included in the PixieFail set.
5
What is the significance of the UEFI specification in relation to these vulnerabilities?
The UEFI specification is crucial for system boot processes, making vulnerabilities in EDK II particularly impactful for enterprise security.