#pixiefail — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pixiefail, aggregated by home.social.
-
RT @quarkslab
Is remote code execution in UEFI firmware possible?
Yes it is.
Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers.
Full details by @fdfalcon and @4Dgifts in our new blog post: https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html -
@quarkslab @fdfalcon @4Dgifts L’analyse et les conseils du @CERT_FR pour protéger vos machines de #PixieFAIL : https://www.cert.ssi.gouv.fr/actualite/CERTFR-2024-ACT-004/
-
CW: Long thread/27
That badware is running in "Ring -1" - a zone of privilege that overrides the operating system itself.
Here's the bad news: UEFI malware has already been detected in the wild:
https://securelist.com/cosmicstrand-uefi-firmware-rootkit/106973/
And here's the worst news: researchers have just identified *another* exploitable UEFI bug, dubbed #Pixiefail:
27/
-
Excellent #security research work and blog post by @quarkslab 🔥
#PixieFail: Nine #vulnerabilities in #Tianocore's EDK II #IPv6 network stack
Congrats to @4Dgifts who’s #stillhacking after so many years. Inspiring 🙏
-
New UEFI vulnerabilities send firmware devs across an entire ecosystem scrambling - Enlarge (credit: Nadezhda Kozhedub)
UEFI firmware from five of... - https://arstechnica.com/?p=1996543 #vulnerabilities #pixiefail #security #exploits #biz #uefi
-
#PixieFAIL : Nine vulnerabilities in Tianocore's EDK II IPv6 network stack. Nine vulnerabilities that affect EDK II, the de-facto open source reference implementation of the UEFI specification and possibly all implementations derived from it. - https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html #security
-
Here's the writeup on #PixieFail, 9 vulns in the UEFI reference architecture that could enable exploitation over PXE network boot using IPv6. As near as I can tell, what has been demonstrated is underflow/overflows, but no successful exploitation.
blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html