VulnerabilityModified
CVE-2019-18279
In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application to gain elevated privileges.
HIGH 8.8EPSS 1.26%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application to gain elevated privileges. Adverse impacts are limited to the Windows environment and there is no known direct impact to the UEFI firmware. This was fixed in late June 2019.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- phoenix/securecore technology
- Source
- cve@mitre.org
References
- https://eclypsium.com/2019/08/10/screwed-drivers-signed-sealed-delivered/Third Party Advisory
- https://eclypsium.com/wp-content/uploads/2019/08/EXTERNAL-Get-off-the-kernel-if-you-cant-drive-DEFCON27.pdfThird Party Advisory
- https://www.phoenix.com/content/uploads/Security-Newsletter-September-2019.pdfVendor Advisory
- https://eclypsium.com/2019/08/10/screwed-drivers-signed-sealed-delivered/Third Party Advisory
- https://eclypsium.com/wp-content/uploads/2019/08/EXTERNAL-Get-off-the-kernel-if-you-cant-drive-DEFCON27.pdfThird Party Advisory
- https://www.phoenix.com/content/uploads/Security-Newsletter-September-2019.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.