CVE-2019-18279
Summary
| CVE | CVE-2019-18279 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-13 18:15:00 UTC |
| Updated | 2023-12-08 18:54:00 UTC |
| Description | In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application to gain elevated privileges. Adverse impacts are limited to the Windows environment and there is no known direct impact to the UEFI firmware. This was fixed in late June 2019. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phoenix | Securecore Technology | All | All | All | All |
| Operating System | Phoenix | Securecore Technology | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Screwed Drivers – Signed, Sealed, Delivered - Eclypsium | MISC | eclypsium.com | Third Party Advisory |
| Phoenix404 – Phoenix Technologies – Leading PC Innovation since 1979 | CONFIRM | www.phoenix.com | Vendor Advisory |
| eclypsium.com/wp-content/uploads/2019/08/EXTERNAL-Get-off-the-kernel-if-you... | MISC | eclypsium.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.