Amazing #PixieFAIL work by @fdfalcon and @4Dgifts making EDK II — the reference implementation of UEFI — exploitable during the network boot process.
https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html
PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack.

This blog post provides details about nine vulnerabilities affecting the IPv6 network protocol stack of EDK II, TianoCore's open source reference implementation of UEFI.

Quarkslab's blog