


Lenovo has issued a patch in May, Phoenix UEFI firmware vulnerability disclosed: affecting hundreds of Intel PC CPU models
According to news from this site on June 21, Phoenix SecureCore UEFI firmware was exposed to a security vulnerability, affecting hundreds of Intel CPU devices. Lenovo has released a new firmware update to fix the vulnerability.
This site learned from reports that the vulnerability tracking number is CVE-2024-0762, known as "UEFICANHAZBUFFEROVERFLOW", which exists in the Trusted Platform Module (TPM) configuration in Phoenix UEFI firmware and is a buffer Area overflow vulnerability can be exploited to execute arbitrary code on vulnerable devices.
The vulnerability was discovered by Eclypsium, who discovered the vulnerability on Lenovo ThinkPad X1 Carbon 7th generation and X1 Yoga 4th generation devices, and later confirmed to Phoenix that it affects the SecureCore firmware of the following Intel CPUs:
Alder Lake
Coffee Lake
Comet Lake
Ice Lake
Jasper Lake
Kaby Lake
Meteor Lake
Raptor Lake
Rocket Lake
Tiger Lake
This vulnerability is possible due to the large number of Intel CPUs using this firmware Affecting hundreds of models from Lenovo, Dell, Acer and HP.
Eclypsium says the vulnerability they discovered is a buffer overflow in the System Management Mode (SMM) subsystem of the Phoenix SecureCore firmware, allowing an attacker to overwrite adjacent memory.
If the memory is overwritten with the correct data, it is possible for an attacker to escalate privileges and gain code execution capabilities in the firmware to install boot kit malware.
Phoenix issued a warning in April, and Lenovo released new firmware in May that fixed the vulnerability in more than 150 different models, but other manufacturers have not yet fully followed up on the fixes.
The above is the detailed content of Lenovo has issued a patch in May, Phoenix UEFI firmware vulnerability disclosed: affecting hundreds of Intel PC CPU models. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

According to news from this website on July 25, the source Jaykihn posted a tweet on the X platform yesterday (July 24), sharing the running score data of the Intel Core Ultra9285K "ArrowLake-S" desktop processor. The results show that it is better than the Core 14900K 18% faster. This site quoted the content of the tweet. The source shared the running scores of the ES2 and QS versions of the Intel Core Ultra9285K processor and compared them with the Core i9-14900K processor. According to reports, the TD of ArrowLake-SQS when running workloads such as CinebenchR23, Geekbench5, SpeedoMeter, WebXPRT4 and CrossMark

According to news from this website on July 28, foreign media TechRader reported that Fujitsu introduced in detail the FUJITSU-MONAKA (hereinafter referred to as MONAKA) processor planned to be shipped in 2027. MONAKACPU is based on the "cloud native 3D many-core" architecture and adopts the Arm instruction set. It is oriented to the data center, edge and telecommunications fields. It is suitable for AI computing and can realize mainframe-level RAS1. Fujitsu said that MONAKA will achieve a leap in energy efficiency and performance: thanks to technologies such as ultra-low voltage (ULV) technology, the CPU can achieve 2 times the energy efficiency of competing products in 2027, and cooling does not require water cooling; in addition, the application performance of the processor It can also reach twice as much as your opponent. In terms of instructions, MONAKA is equipped with vector

IntelArrowLakeisexpectedtobebasedonthesameprocessorarchitectureasLunarLake,meaningthatIntel'sbrandnewLionCoveperformancecoreswillbecombinedwiththeeconomicalSkymontefficiencycores.WhileLunarLakeisonlyavailableasava

This website reported on July 3 that in order to meet the diversified needs of modern enterprises, MSIIPC, a subsidiary of MSI, has recently launched the MS-C918, an industrial mini host. No public price has been found yet. MS-C918 is positioned for enterprises that focus on cost-effectiveness, ease of use and portability. It is specially designed for non-critical environments and provides a 3-year service life guarantee. MS-C918 is a handheld industrial computer, using Intel AlderLake-NN100 processor, specially tailored for ultra-low power solutions. The main functions and features of MS-C918 attached to this site are as follows: Compact size: 80 mm x 80 mm x 36 mm, palm size, easy to operate and hidden behind the monitor. Display function: via 2 HDMI2.

According to news from this website on August 8, MSI and ASUS today launched a beta version of BIOS containing the 0x129 microcode update for some Z790 motherboards in response to the instability issues in Intel Core 13th and 14th generation desktop processors. ASUS's first batch of motherboards to provide BIOS updates include: ROGMAXIMUSZ790HEROBetaBios2503ROGMAXIMUSZ790DARKHEROBetaBios1503ROGMAXIMUSZ790HEROBTFBetaBios1503ROGMAXIMUSZ790HEROEVA-02 joint version BetaBios2503ROGMAXIMUSZ790A

According to news from this site on June 19, as part of the 2024 IEEEVLSI seminar activities, Intel recently introduced the technical details of the Intel3 process node on its official website. Intel's latest generation of FinFET transistor technology is Intel's latest generation of FinFET transistor technology. Compared with Intel4, it has added steps to use EUV. It will also be a node family that provides foundry services for a long time, including basic Intel3 and three variant nodes. Among them, Intel3-E natively supports 1.2V high voltage, which is suitable for the manufacturing of analog modules; while the future Intel3-PT will further improve the overall performance and support finer 9μm pitch TSV and hybrid bonding. Intel claims that as its

According to news from this site on July 16, following the revelation of the specifications of the ArrowLake desktop processor and the BartlettLake desktop processor, blogger @jaykihn0 released the specifications of the mobile U and H versions of the Intel PantherLake processor in the early morning. The Panther Lake mobile processor is expected to be named the Core Ultra300 series and will be available in the following versions: PTL-U: 4P+0E+4LPE+4Xe, 15WPL1PTL-H: 4P+8E+4LPE+12Xe, 25WPL1PTL-H: 4P+8E+4LPE+ 4Xe, 25WPL1. The blogger also released the 12Xe nuclear display version of the PantherLake processor.

According to news from this website on July 24, the Core Ultra5236V, the more entry-level model of Intel’s Lunar Lake mobile processor, appeared in the Geekbench benchmark database today. The running score data shows that the Core Ultra5236V tested this time is a Lenovo model with a base frequency of 2.1GHz and the highest frequency reached in the running score is 4675MHz. In Geekbench6.1, it achieved a single-core score of 2021 points and a multi-core score of 5743 points. Note from this site: Due to unclear test conditions, the results of this test are significantly lower than LunarLake's normal range. Other test results are attached for reference. ▲LunarLake benchmark Intel Core Ultr in Geekbench database
