home.social

#pixiefail — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pixiefail, aggregated by home.social.

  1. RT @quarkslab
    Is remote code execution in UEFI firmware possible?
    Yes it is.
    Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers.
    Full details by @fdfalcon and @4Dgifts in our new blog post: blog.quarkslab.com/pixiefail-n

  2. RT @quarkslab
    Is remote code execution in UEFI firmware possible?
    Yes it is.
    Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers.
    Full details by @fdfalcon and @4Dgifts in our new blog post: blog.quarkslab.com/pixiefail-n

  3. RT @quarkslab
    Is remote code execution in UEFI firmware possible?
    Yes it is.
    Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers.
    Full details by @fdfalcon and @4Dgifts in our new blog post: blog.quarkslab.com/pixiefail-n

  4. RT @quarkslab
    Is remote code execution in UEFI firmware possible?
    Yes it is.
    Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers.
    Full details by @fdfalcon and @4Dgifts in our new blog post: blog.quarkslab.com/pixiefail-n

  5. #PixieFail #UEFI の欠陥により、数百万台のコンピュータが RCE、DoS、およびデータ盗難にさらされる 」: The Hacker News

    「最新のコンピュータで広く使用されている Unified Extensible Firmware Interface ( UEFI )仕様のオープンソース参照実装の TCP/IP ネットワーク プロトコル スタックに、複数のセキュリティ脆弱性が明らかになりました 。

    AMI、Intel、Insyde、Phoenix Technologies の UEFI ファームウェア (オペレーティング システムの起動 を担当) がこの欠点の影響を受けます。 」

    thehackernews.com/2024/01/pixi

    #prattohome #TheHackerNews

  6. #PixieFail #UEFI の欠陥により、数百万台のコンピュータが RCE、DoS、およびデータ盗難にさらされる 」: The Hacker News

    「最新のコンピュータで広く使用されている Unified Extensible Firmware Interface ( UEFI )仕様のオープンソース参照実装の TCP/IP ネットワーク プロトコル スタックに、複数のセキュリティ脆弱性が明らかになりました 。

    AMI、Intel、Insyde、Phoenix Technologies の UEFI ファームウェア (オペレーティング システムの起動 を担当) がこの欠点の影響を受けます。 」

    thehackernews.com/2024/01/pixi

    #prattohome #TheHackerNews

  7. #PixieFail #UEFI の欠陥により、数百万台のコンピュータが RCE、DoS、およびデータ盗難にさらされる 」: The Hacker News

    「最新のコンピュータで広く使用されている Unified Extensible Firmware Interface ( UEFI )仕様のオープンソース参照実装の TCP/IP ネットワーク プロトコル スタックに、複数のセキュリティ脆弱性が明らかになりました 。

    AMI、Intel、Insyde、Phoenix Technologies の UEFI ファームウェア (オペレーティング システムの起動 を担当) がこの欠点の影響を受けます。 」

    thehackernews.com/2024/01/pixi

    #prattohome #TheHackerNews

  8. CW: Long thread/27

    That badware is running in "Ring -1" - a zone of privilege that overrides the operating system itself.

    Here's the bad news: UEFI malware has already been detected in the wild:

    securelist.com/cosmicstrand-ue

    And here's the worst news: researchers have just identified *another* exploitable UEFI bug, dubbed #Pixiefail:

    blog.quarkslab.com/pixiefail-n

    27/

  9. CW: Long thread/27

    That badware is running in "Ring -1" - a zone of privilege that overrides the operating system itself.

    Here's the bad news: UEFI malware has already been detected in the wild:

    securelist.com/cosmicstrand-ue

    And here's the worst news: researchers have just identified *another* exploitable UEFI bug, dubbed #Pixiefail:

    blog.quarkslab.com/pixiefail-n

    27/

  10. CW: Long thread/27

    That badware is running in "Ring -1" - a zone of privilege that overrides the operating system itself.

    Here's the bad news: UEFI malware has already been detected in the wild:

    securelist.com/cosmicstrand-ue

    And here's the worst news: researchers have just identified *another* exploitable UEFI bug, dubbed #Pixiefail:

    blog.quarkslab.com/pixiefail-n

    27/

  11. CW: Long thread/27

    That badware is running in "Ring -1" - a zone of privilege that overrides the operating system itself.

    Here's the bad news: UEFI malware has already been detected in the wild:

    securelist.com/cosmicstrand-ue

    And here's the worst news: researchers have just identified *another* exploitable UEFI bug, dubbed #Pixiefail:

    blog.quarkslab.com/pixiefail-n

    27/

  12. CW: Long thread/27

    That badware is running in "Ring -1" - a zone of privilege that overrides the operating system itself.

    Here's the bad news: UEFI malware has already been detected in the wild:

    securelist.com/cosmicstrand-ue

    And here's the worst news: researchers have just identified *another* exploitable UEFI bug, dubbed #Pixiefail:

    blog.quarkslab.com/pixiefail-n

    27/

  13. New UEFI vulnerabilities send firmware devs across an entire ecosystem scrambling - Enlarge (credit: Nadezhda Kozhedub)

    UEFI firmware from five of... - arstechnica.com/?p=1996543 #vulnerabilities #pixiefail #security #exploits #biz#uefi

  14. New UEFI vulnerabilities send firmware devs across an entire ecosystem scrambling - Enlarge (credit: Nadezhda Kozhedub)

    UEFI firmware from five of... - arstechnica.com/?p=1996543 #vulnerabilities #pixiefail #security #exploits #biz#uefi

  15. New UEFI vulnerabilities send firmware devs across an entire ecosystem scrambling - Enlarge (credit: Nadezhda Kozhedub)

    UEFI firmware from five of... - arstechnica.com/?p=1996543 #vulnerabilities #pixiefail #security #exploits #biz#uefi

  16. New UEFI vulnerabilities send firmware devs across an entire ecosystem scrambling - Enlarge (credit: Nadezhda Kozhedub)

    UEFI firmware from five of... - arstechnica.com/?p=1996543 #vulnerabilities #pixiefail #security #exploits #biz#uefi

  17. New UEFI vulnerabilities send firmware devs across an entire ecosystem scrambling - Enlarge (credit: Nadezhda Kozhedub)

    UEFI firmware from five of... - arstechnica.com/?p=1996543 #vulnerabilities #pixiefail #security #exploits #biz#uefi

  18. #PixieFAIL : Nine vulnerabilities in Tianocore's EDK II IPv6 network stack. Nine vulnerabilities that affect EDK II, the de-facto open source reference implementation of the UEFI specification and possibly all implementations derived from it. - blog.quarkslab.com/pixiefail-n #security

  19. : Nine vulnerabilities in Tianocore's EDK II IPv6 network stack. Nine vulnerabilities that affect EDK II, the de-facto open source reference implementation of the UEFI specification and possibly all implementations derived from it. - blog.quarkslab.com/pixiefail-n

  20. #PixieFAIL : Nine vulnerabilities in Tianocore's EDK II IPv6 network stack. Nine vulnerabilities that affect EDK II, the de-facto open source reference implementation of the UEFI specification and possibly all implementations derived from it. - blog.quarkslab.com/pixiefail-n #security

  21. Here's the writeup on #PixieFail, 9 vulns in the UEFI reference architecture that could enable exploitation over PXE network boot using IPv6. As near as I can tell, what has been demonstrated is underflow/overflows, but no successful exploitation.

    blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html

  22. Here's the writeup on #PixieFail, 9 vulns in the UEFI reference architecture that could enable exploitation over PXE network boot using IPv6. As near as I can tell, what has been demonstrated is underflow/overflows, but no successful exploitation.

    blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html

  23. Here's the writeup on #PixieFail, 9 vulns in the UEFI reference architecture that could enable exploitation over PXE network boot using IPv6. As near as I can tell, what has been demonstrated is underflow/overflows, but no successful exploitation.

    blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html

  24. Here's the writeup on #PixieFail, 9 vulns in the UEFI reference architecture that could enable exploitation over PXE network boot using IPv6. As near as I can tell, what has been demonstrated is underflow/overflows, but no successful exploitation.

    blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html

  25. Here's the writeup on #PixieFail, 9 vulns in the UEFI reference architecture that could enable exploitation over PXE network boot using IPv6. As near as I can tell, what has been demonstrated is underflow/overflows, but no successful exploitation.

    blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html