A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
A340-22icb
Subscribe
A340-22icb Firmware
Subscribe
A340-22ick
Subscribe
A340-22ick Firmware
Subscribe
A340-24icb
Subscribe
A340-24icb Firmware
Subscribe
A340-24ick
Subscribe
A340-24ick Firmware
Subscribe
A540-24icb
Subscribe
A540-24icb Firmware
Subscribe
A540-27icb
Subscribe
A540-27icb Firmware
Subscribe
Ideacentre 5-14iob6
Subscribe
Ideacentre 5-14iob6 Firmware
Subscribe
Ideacentre 510s-07icb
Subscribe
Ideacentre 510s-07icb Firmware
Subscribe
Ideacentre 510s-07ick
Subscribe
Ideacentre 510s-07ick Firmware
Subscribe
Ideacentre Aio 3-22ada6
Subscribe
Ideacentre Aio 3-22ada6 Firmware
Subscribe
Ideacentre Aio 3-22iil5
Subscribe
Ideacentre Aio 3-22iil5 Firmware
Subscribe
Ideacentre Aio 3-22itl6
Subscribe
Ideacentre Aio 3-22itl6 Firmware
Subscribe
Ideacentre Aio 3-24ada6
Subscribe
Ideacentre Aio 3-24ada6 Firmware
Subscribe
Ideacentre Aio 3-24iil5
Subscribe
Ideacentre Aio 3-24iil5 Firmware
Subscribe
Ideacentre Aio 3-24itl6
Subscribe
Ideacentre Aio 3-24itl6 Firmware
Subscribe
Ideacentre Aio 3-27itl6
Subscribe
Ideacentre Aio 3-27itl6 Firmware
Subscribe
Ideacentre Creator 5-14iob6
Subscribe
Ideacentre Creator 5-14iob6 Firmware
Subscribe
Ideacentre Gaming 5-14iob6
Subscribe
Ideacentre Gaming 5-14iob6 Firmware
Subscribe
Se30
Subscribe
Se30 Firmware
Subscribe
Thinkcentre M600
Subscribe
Thinkcentre M600 Firmware
Subscribe
Thinkcentre M700 Tiny
Subscribe
Thinkcentre M700 Tiny Firmware
Subscribe
Thinkcentre M70a
Subscribe
Thinkcentre M70a Firmware
Subscribe
Thinkcentre M710e
Subscribe
Thinkcentre M710e Firmware
Subscribe
Thinkcentre M710q
Subscribe
Thinkcentre M710q \(10yc\)
Subscribe
Thinkcentre M710q \(10yc\) Firmware
Subscribe
Thinkcentre M710q Firmware
Subscribe
Thinkcentre M710s
Subscribe
Thinkcentre M710s Firmware
Subscribe
Thinkcentre M710t
Subscribe
Thinkcentre M710t Firmware
Subscribe
Thinkcentre M720e
Subscribe
Thinkcentre M720e Firmware
Subscribe
Thinkcentre M75n
Subscribe
Thinkcentre M75n Firmware
Subscribe
Thinkcentre M800
Subscribe
Thinkcentre M800 Firmware
Subscribe
Thinkcentre M810z
Subscribe
Thinkcentre M810z Firmware
Subscribe
Thinkcentre M820z
Subscribe
Thinkcentre M820z Firmware
Subscribe
Thinkcentre M900
Subscribe
Thinkcentre M900 Firmware
Subscribe
Thinkcentre M900x
Subscribe
Thinkcentre M900x Firmware
Subscribe
Thinkcentre M90a \(gen 2\)
Subscribe
Thinkcentre M90a \(gen 2\) Firmware
Subscribe
Thinkcentre M910q
Subscribe
Thinkcentre M910q Firmware
Subscribe
Thinkcentre M910s
Subscribe
Thinkcentre M910s Firmware
Subscribe
Thinkcentre M910t
Subscribe
Thinkcentre M910t Firmware
Subscribe
Thinkcentre M910x
Subscribe
Thinkcentre M910x Firmware
Subscribe
Thinkstation P310
Subscribe
Thinkstation P310 Firmware
Subscribe
Thinkstation P320
Subscribe
Thinkstation P320 Firmware
Subscribe
Thinkstation P320 Tiny
Subscribe
Thinkstation P320 Tiny Firmware
Subscribe
V30a-22iml
Subscribe
V30a-22iml Firmware
Subscribe
V30a-24iml
Subscribe
V30a-24iml Firmware
Subscribe
V410z
Subscribe
V410z Firmware
Subscribe
V50t-13iob G2
Subscribe
V50t-13iob G2 Firmware
Subscribe
V520
Subscribe
V520 Firmware
Subscribe
V520s
Subscribe
V520s Firmware
Subscribe
V530-15icb
Subscribe
V530-15icb Firmware
Subscribe
V530-15icr
Subscribe
V530-15icr Firmware
Subscribe
V530s-07icb
Subscribe
V530s-07icb Firmware
Subscribe
V530s-07icr
Subscribe
V530s-07icr Firmware
Subscribe
V540-24iwl
Subscribe
V540-24iwl Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-34069 | A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. |
Fixes
Solution
Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-77639.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-77639 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-03T17:16:04.358Z
Reserved: 2022-01-24T00:00:00
Link: CVE-2021-4211
No data.
Status : Modified
Published: 2022-04-22T21:15:10.007
Modified: 2024-11-21T06:37:09.520
Link: CVE-2021-4211
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD