Description


A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Related CPE's








o

lenovo

ideacentre_3-07imb05_firmware

2

h

lenovo

ideacentre_3-07imb05

2





o

lenovo

ideacentre_5-14imb05_firmware

2

h

lenovo

ideacentre_5-14imb05

2











o

lenovo

ideacentre_aio_3-24alc6_firmware

2

h

lenovo

ideacentre_aio_3-24alc6

2































o

lenovo

legion_t7-34imz5_firmware

2

h

lenovo

legion_t7-34imz5

2































































o

lenovo

ideacentre_m75s_gen_2_firmware

3




o

lenovo

ideacentre_m75t_gen_2_firmware

3












































































o

lenovo

ideacentre_t540-15ama_g_firmware

2

h

lenovo

ideacentre_t540-15ama_g

2





























































































































































































o

lenovo

thinkagile_hx3331_firmware

2

h

lenovo

thinkagile_hx3331

2





























o

lenovo

thinkagile_hx7531_firmware

2

h

lenovo

thinkagile_hx7531

2

















































































































































o

lenovo

thinkstation_p720_workstation_firmware

2


o

lenovo

thinkstation_p920_workstation_firmware

2









Weaknesses



CWE-120


CWE-120

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

6.7 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2023-01-30T22:15:12.387

2 years ago

Last modified

2023-02-08T22:20:28.487

2 years ago