Jan. 16, 2024, 2:26 p.m. |

CERT Recently Published Vulnerability Notes kb.cert.org

Overview


Multiple vulnerabilities were discovered in the TCP/IP stack (NetworkPkg) of Tianocore EDKII, an open source implementation of Unified Extensible Firmware Interface (UEFI). Researchers at Quarkslab have identified a total of 9 vulnerabilities that if exploited via network can lead to remote code execution, DoS attacks, DNS cache poisoning, and/or potential leakage of sensitive information. Quarkslab have labeled these set of related vulnerabilities as PixieFail.


Description


UEFI represents a contemporary firmware standard pivotal in initiating the operating system on modern …

attacks cache cache poisoning can code code execution dns dns cache poisoning dos exploited firmware implementation interface ip stack network open source poisoning quarkslab remote code remote code execution researchers stack tcp tianocore uefi vulnerabilities

More from kb.cert.org / CERT Recently Published Vulnerability Notes

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States