Home Hardware Tutorial Hardware News Lenovo has issued a patch in May, Phoenix UEFI firmware vulnerability disclosed: affecting hundreds of Intel PC CPU models

Lenovo has issued a patch in May, Phoenix UEFI firmware vulnerability disclosed: affecting hundreds of Intel PC CPU models

Jun 22, 2024 am 10:27 AM
cpu loopholes uefi Intel

According to news from this site on June 21, Phoenix SecureCore UEFI firmware was exposed to a security vulnerability, affecting hundreds of Intel CPU devices. Lenovo has released a new firmware update to fix the vulnerability.

联想 5 月已发补丁,Phoenix UEFI 固件漏洞披露:影响数百款英特尔 PC CPU 型号

This site learned from reports that the vulnerability tracking number is CVE-2024-0762, known as "UEFICANHAZBUFFEROVERFLOW", which exists in the Trusted Platform Module (TPM) configuration in Phoenix UEFI firmware and is a buffer Area overflow vulnerability can be exploited to execute arbitrary code on vulnerable devices.

The vulnerability was discovered by Eclypsium, who discovered the vulnerability on Lenovo ThinkPad X1 Carbon 7th generation and X1 Yoga 4th generation devices, and later confirmed to Phoenix that it affects the SecureCore firmware of the following Intel CPUs:

Alder Lake

Coffee Lake

Comet Lake

Ice Lake

Jasper Lake

Kaby Lake

Meteor Lake

Raptor Lake

Rocket Lake

Tiger Lake

This vulnerability is possible due to the large number of Intel CPUs using this firmware Affecting hundreds of models from Lenovo, Dell, Acer and HP.

Eclypsium says the vulnerability they discovered is a buffer overflow in the System Management Mode (SMM) subsystem of the Phoenix SecureCore firmware, allowing an attacker to overwrite adjacent memory.

If the memory is overwritten with the correct data, it is possible for an attacker to escalate privileges and gain code execution capabilities in the firmware to install boot kit malware.

Phoenix issued a warning in April, and Lenovo released new firmware in May that fixed the vulnerability in more than 150 different models, but other manufacturers have not yet fully followed up on the fixes.

The above is the detailed content of Lenovo has issued a patch in May, Phoenix UEFI firmware vulnerability disclosed: affecting hundreds of Intel PC CPU models. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Intel Core Ultra 9 285K processor exposed: CineBench R23 multi-core running score is 18% higher than i9-14900K Intel Core Ultra 9 285K processor exposed: CineBench R23 multi-core running score is 18% higher than i9-14900K Jul 25, 2024 pm 12:25 PM

According to news from this website on July 25, the source Jaykihn posted a tweet on the X platform yesterday (July 24), sharing the running score data of the Intel Core Ultra9285K "ArrowLake-S" desktop processor. The results show that it is better than the Core 14900K 18% faster. This site quoted the content of the tweet. The source shared the running scores of the ES2 and QS versions of the Intel Core Ultra9285K processor and compared them with the Core i9-14900K processor. According to reports, the TD of ArrowLake-SQS when running workloads such as CinebenchR23, Geekbench5, SpeedoMeter, WebXPRT4 and CrossMark

144-core, 3D-stacked SRAM: Fujitsu details next-generation data center processor MONAKA 144-core, 3D-stacked SRAM: Fujitsu details next-generation data center processor MONAKA Jul 29, 2024 am 11:40 AM

According to news from this website on July 28, foreign media TechRader reported that Fujitsu introduced in detail the FUJITSU-MONAKA (hereinafter referred to as MONAKA) processor planned to be shipped in 2027. MONAKACPU is based on the "cloud native 3D many-core" architecture and adopts the Arm instruction set. It is oriented to the data center, edge and telecommunications fields. It is suitable for AI computing and can realize mainframe-level RAS1. Fujitsu said that MONAKA will achieve a leap in energy efficiency and performance: thanks to technologies such as ultra-low voltage (ULV) technology, the CPU can achieve 2 times the energy efficiency of competing products in 2027, and cooling does not require water cooling; in addition, the application performance of the processor It can also reach twice as much as your opponent. In terms of instructions, MONAKA is equipped with vector

Leak reveals key specs of Intel Arrow Lake-U, -H, -HX and -S Leak reveals key specs of Intel Arrow Lake-U, -H, -HX and -S Jun 15, 2024 pm 09:49 PM

IntelArrowLakeisexpectedtobebasedonthesameprocessorarchitectureasLunarLake,meaningthatIntel'sbrandnewLionCoveperformancecoreswillbecombinedwiththeeconomicalSkymontefficiencycores.WhileLunarLakeisonlyavailableasava

MSI launches new MS-C918 mini console with Intel Alder Lake-N N100 processor MSI launches new MS-C918 mini console with Intel Alder Lake-N N100 processor Jul 03, 2024 am 11:33 AM

This website reported on July 3 that in order to meet the diversified needs of modern enterprises, MSIIPC, a subsidiary of MSI, has recently launched the MS-C918, an industrial mini host. No public price has been found yet. MS-C918 is positioned for enterprises that focus on cost-effectiveness, ease of use and portability. It is specially designed for non-critical environments and provides a 3-year service life guarantee. MS-C918 is a handheld industrial computer, using Intel AlderLake-NN100 processor, specially tailored for ultra-low power solutions. The main functions and features of MS-C918 attached to this site are as follows: Compact size: 80 mm x 80 mm x 36 mm, palm size, easy to operate and hidden behind the monitor. Display function: via 2 HDMI2.

ASUS releases BIOS update for Z790 motherboards to alleviate instability issues with Intel's 13th/14th generation Core processors ASUS releases BIOS update for Z790 motherboards to alleviate instability issues with Intel's 13th/14th generation Core processors Aug 09, 2024 am 12:47 AM

According to news from this website on August 8, MSI and ASUS today launched a beta version of BIOS containing the 0x129 microcode update for some Z790 motherboards in response to the instability issues in Intel Core 13th and 14th generation desktop processors. ASUS's first batch of motherboards to provide BIOS updates include: ROGMAXIMUSZ790HEROBetaBios2503ROGMAXIMUSZ790DARKHEROBetaBios1503ROGMAXIMUSZ790HEROBTFBetaBios1503ROGMAXIMUSZ790HEROEVA-02 joint version BetaBios2503ROGMAXIMUSZ790A

Intel explains in detail the Intel 3 process: applying more EUV lithography, increasing the frequency of the same power consumption by up to 18% Intel explains in detail the Intel 3 process: applying more EUV lithography, increasing the frequency of the same power consumption by up to 18% Jun 19, 2024 pm 10:53 PM

According to news from this site on June 19, as part of the 2024 IEEEVLSI seminar activities, Intel recently introduced the technical details of the Intel3 process node on its official website. Intel's latest generation of FinFET transistor technology is Intel's latest generation of FinFET transistor technology. Compared with Intel4, it has added steps to use EUV. It will also be a node family that provides foundry services for a long time, including basic Intel3 and three variant nodes. Among them, Intel3-E natively supports 1.2V high voltage, which is suitable for the manufacturing of analog modules; while the future Intel3-PT will further improve the overall performance and support finer 9μm pitch TSV and hybrid bonding. Intel claims that as its

Intel Panther Lake mobile processor specifications exposed: up to '4+8+4' 16-core CPU, 12 Xe3 core display Intel Panther Lake mobile processor specifications exposed: up to '4+8+4' 16-core CPU, 12 Xe3 core display Jul 18, 2024 pm 04:43 PM

According to news from this site on July 16, following the revelation of the specifications of the ArrowLake desktop processor and the BartlettLake desktop processor, blogger @jaykihn0 released the specifications of the mobile U and H versions of the Intel PantherLake processor in the early morning. The Panther Lake mobile processor is expected to be named the Core Ultra300 series and will be available in the following versions: PTL-U: 4P+0E+4LPE+4Xe, 15WPL1PTL-H: 4P+8E+4LPE+12Xe, 25WPL1PTL-H: 4P+8E+4LPE+ 4Xe, 25WPL1. The blogger also released the 12Xe nuclear display version of the PantherLake processor.

Codenamed Lunar Lake, Intel Core Ultra 5 236V mobile processor appears on Geekbench for the first time Codenamed Lunar Lake, Intel Core Ultra 5 236V mobile processor appears on Geekbench for the first time Jul 25, 2024 am 01:08 AM

According to news from this website on July 24, the Core Ultra5236V, the more entry-level model of Intel’s Lunar Lake mobile processor, appeared in the Geekbench benchmark database today. The running score data shows that the Core Ultra5236V tested this time is a Lenovo model with a base frequency of 2.1GHz and the highest frequency reached in the running score is 4675MHz. In Geekbench6.1, it achieved a single-core score of 2021 points and a multi-core score of 5743 points. Note from this site: Due to unclear test conditions, the results of this test are significantly lower than LunarLake's normal range. Other test results are attached for reference. ▲LunarLake benchmark Intel Core Ultr in Geekbench database

See all articles