Phoenix SecureCore UEFI Variable Handling Vulnerability Leading to Input Data Manipulation

Vulnerability

A vulnerability exists in Phoenix SecureCore firmware for various Intel processor families, including Kaby Lake, Coffee Lake, Comet Lake, and Ice Lake. This vulnerability arises from improper handling of UEFI variables, allowing for unsafe memory access that could result in temporary denial of service. The issue affects SecureCore for Intel Kaby Lake versions prior to 4.0.1.1012, Coffee Lake versions prior to 4.1.0.568, Comet Lake versions prior to 4.2.1.292, and Ice Lake versions prior to 4.2.0.334.

Impact

Exploitation of this vulnerability could lead to unsafe memory access, causing a temporary denial of service.

Remediation

Users are advised to update their firmware to the latest version and contact their hardware vendor for device-specific information.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
2.8
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.