Phoenixtech maintains a narrowly scoped product line centered on firmware and system-level utilities such as SecureCore Technology and WinFlash, which occupy a specialized but notably represented position in the firmware and BIOS management landscape. The vendor's recurring vulnerability patterns cluster around low-level input handling and access control, including buffer overflows, insufficient validation of exceptional conditions, and improper IOCTL access restrictions—weakness classes typical of firmware and privileged system software where memory safety and permission boundaries are critical. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phoenixtech over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0762HIGH Potential buffer overflow
in unsafe UEFI variable handling
in Phoenix SecureCore™ for select Intel platforms
This issue affects:
Phoenix
SecureCore™ for Intel Kaby Lake: f | May 14, 2024 | 7.8 | 26 | NO | NO |
CVE-2023-5058HIGH Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or a | Dec 7, 2023 | 7.8 | 25 | NO | NO |
CVE-2024-1598HIGH Potential buffer overflow
in unsafe UEFI variable handling
in Phoenix SecureCore™ for Intel Gemini Lake.This issue affects:
SecureCore™ for Intel Gemini Lake: from 4.1.0.1 befo | May 14, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-35841HIGH Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects | May 14, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-31100HIGH Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification.
This issue affects SecureCore™ Technology™ 4:
* from 4 | Nov 15, 2023 | 7.1 | 19 | NO | NO |
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore Technology 4 allows Input Data Manipulation.This issue affects SecureCore Technology 4: fro | May 13, 2025 | 3.3 | 14 | NO | NO |
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for In | Jan 14, 2025 | 3.3 | 12 | NO | NO |
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for In | Jan 14, 2025 | 3.3 | 12 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phoenixtech.
Media articles that mention a CVE ID that affects a product developed by Phoenixtech — matched by CVE ID, not by vendor name.