PixieFAIL — vulnerabilities in the UEFI firmware network stack used for PXE booting

Nine vulnerabilities, collectively codenamed PixieFAIL, have been identified in UEFI firmware based on the open source platform TianoCore EDK2, commonly used in server systems. These vulnerabilities exist in the firmware's network stack, which is used for network booting (PXE). The most critical vulnerabilities allow an unauthenticated attacker to execute their code remotely at the firmware level on systems that permit PXE booting using IPv6.

Less severe issues lead to denial of service (boot blocking), information leakage, DNS cache poisoning, and interception of TCP sessions. Most vulnerabilities can be exploited from the local network, but some allow attacks from the external network as well. A typical attack scenario involves monitoring traffic on the local network and sending specially crafted packets upon detecting activity related to PXE system boot. Access to server the boot process or DHCP server is not required. Prototypes of exploits have been published to demonstrate the attack technique.

UEFI firmware based on the TianoCore EDK2 platform is used by many large companies, cloud providers, data centers, and computing clusters. In particular, the vulnerable NetworkPkg module implementing PXE booting is used in firmware developed by companies such as ARM, Insyde Software (Insyde H20 UEFI BIOS), American Megatrends (AMI Aptio OpenEdition), Phoenix Technologies (SecureCore), Intel, Dell, and Microsoft (Project Mu). It was thought that the vulnerabilities also affect the ChromeOS platform, which has a package of EDK2 in its repository, but Google stated that this package is not used in the firmware for Chromebook devices and that the ChromeOS platform is not susceptible to the issue.

Identified vulnerabilities:

  • CVE-2023-45230 - buffer overflow in the DHCPv6 client code, exploited by sending an excessively long identifier server (Server ID option).
  • CVE-2023-45234 - buffer overflow when processing the option with DNS server parameters passed in the message announcing the presence of a DHCPv6 server.
  • CVE-2023-45235 - buffer overflow when processing the option with the server identifier (Server ID) in proxy server announcement messages for DHCPv6.
  • CVE-2023-45229 - integer underflow occurring when processing IA_NA/IA_TA options in DHCPv6 messages announcing a DHCP server.
  • CVE-2023-45231 — data leak from buffer overflow when processing ND Redirect (Neighbor Discovery) messages with truncated option values.
  • CVE-2023-45232 — infinite loop when parsing unknown options in the Destination Options header.
  • CVE-2023-45233 — infinite loop when parsing PadN option in the packet header.
  • CVE-2023-45236 — use of predictable initial TCP sequence numbers allowing an attacker to hijack TCP connections.
  • CVE-2023-45237 — use of an unreliable pseudo-random number generator that produces predictable values.

Information about the vulnerabilities was submitted to CERT/CC on August 3, 2023, with disclosure originally scheduled for November 2. However, due to the need for a coordinated release of patches covering multiple vendors, the publication date was initially pushed to December 1, then postponed to December 12 and December 19, 2023, but ultimately disclosed on January 16, 2024. Microsoft requested to delay public disclosure until May.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster