High severity8.8NVD Advisory· Published Nov 13, 2019· Updated Jun 17, 2026
CVE-2019-18279
CVE-2019-18279
Description
In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application to gain elevated privileges. Adverse impacts are limited to the Windows environment and there is no known direct impact to the UEFI firmware. This was fixed in late June 2019.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Phoenix SCT/WinFlashdescription
- Range: 1.1.12.0 - 1.5.74.0
Patches
Vulnerability mechanics
References
3- eclypsium.com/2019/08/10/screwed-drivers-signed-sealed-delivered/nvdThird Party Advisory
- eclypsium.com/wp-content/uploads/2019/08/EXTERNAL-Get-off-the-kernel-if-you-cant-drive-DEFCON27.pdfnvdThird Party Advisory
- www.phoenix.com/content/uploads/Security-Newsletter-September-2019.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.