A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Project Subscriptions

Vendors Products
A340-22icb Subscribe
A340-22icb Firmware Subscribe
A340-22ick Subscribe
A340-22ick Firmware Subscribe
A340-24icb Subscribe
A340-24icb Firmware Subscribe
A340-24ick Subscribe
A340-24ick Firmware Subscribe
A540-24icb Subscribe
A540-24icb Firmware Subscribe
A540-27icb Subscribe
A540-27icb Firmware Subscribe
Ideacentre 5-14iob6 Subscribe
Ideacentre 5-14iob6 Firmware Subscribe
Ideacentre 510s-07icb Subscribe
Ideacentre 510s-07icb Firmware Subscribe
Ideacentre 510s-07ick Subscribe
Ideacentre 510s-07ick Firmware Subscribe
Ideacentre Aio 3-22ada6 Subscribe
Ideacentre Aio 3-22ada6 Firmware Subscribe
Ideacentre Aio 3-22iil5 Subscribe
Ideacentre Aio 3-22iil5 Firmware Subscribe
Ideacentre Aio 3-22itl6 Subscribe
Ideacentre Aio 3-22itl6 Firmware Subscribe
Ideacentre Aio 3-24ada6 Subscribe
Ideacentre Aio 3-24ada6 Firmware Subscribe
Ideacentre Aio 3-24iil5 Subscribe
Ideacentre Aio 3-24iil5 Firmware Subscribe
Ideacentre Aio 3-24itl6 Subscribe
Ideacentre Aio 3-24itl6 Firmware Subscribe
Ideacentre Aio 3-27itl6 Subscribe
Ideacentre Aio 3-27itl6 Firmware Subscribe
Ideacentre Creator 5-14iob6 Subscribe
Ideacentre Creator 5-14iob6 Firmware Subscribe
Ideacentre Gaming 5-14iob6 Subscribe
Ideacentre Gaming 5-14iob6 Firmware Subscribe
Se30 Firmware Subscribe
Thinkcentre M600 Subscribe
Thinkcentre M600 Firmware Subscribe
Thinkcentre M700 Tiny Subscribe
Thinkcentre M700 Tiny Firmware Subscribe
Thinkcentre M70a Subscribe
Thinkcentre M70a Firmware Subscribe
Thinkcentre M710e Subscribe
Thinkcentre M710e Firmware Subscribe
Thinkcentre M710q Subscribe
Thinkcentre M710q \(10yc\) Subscribe
Thinkcentre M710q \(10yc\) Firmware Subscribe
Thinkcentre M710q Firmware Subscribe
Thinkcentre M710s Subscribe
Thinkcentre M710s Firmware Subscribe
Thinkcentre M710t Subscribe
Thinkcentre M710t Firmware Subscribe
Thinkcentre M720e Subscribe
Thinkcentre M720e Firmware Subscribe
Thinkcentre M75n Subscribe
Thinkcentre M75n Firmware Subscribe
Thinkcentre M800 Subscribe
Thinkcentre M800 Firmware Subscribe
Thinkcentre M810z Subscribe
Thinkcentre M810z Firmware Subscribe
Thinkcentre M820z Subscribe
Thinkcentre M820z Firmware Subscribe
Thinkcentre M900 Subscribe
Thinkcentre M900 Firmware Subscribe
Thinkcentre M900x Subscribe
Thinkcentre M900x Firmware Subscribe
Thinkcentre M90a \(gen 2\) Subscribe
Thinkcentre M90a \(gen 2\) Firmware Subscribe
Thinkcentre M910q Subscribe
Thinkcentre M910q Firmware Subscribe
Thinkcentre M910s Subscribe
Thinkcentre M910s Firmware Subscribe
Thinkcentre M910t Subscribe
Thinkcentre M910t Firmware Subscribe
Thinkcentre M910x Subscribe
Thinkcentre M910x Firmware Subscribe
Thinkstation P310 Subscribe
Thinkstation P310 Firmware Subscribe
Thinkstation P320 Subscribe
Thinkstation P320 Firmware Subscribe
Thinkstation P320 Tiny Subscribe
Thinkstation P320 Tiny Firmware Subscribe
V30a-22iml Subscribe
V30a-22iml Firmware Subscribe
V30a-24iml Subscribe
V30a-24iml Firmware Subscribe
V410z Firmware Subscribe
V50t-13iob G2 Subscribe
V50t-13iob G2 Firmware Subscribe
V520 Firmware Subscribe
V520s Firmware Subscribe
V530-15icb Subscribe
V530-15icb Firmware Subscribe
V530-15icr Subscribe
V530-15icr Firmware Subscribe
V530s-07icb Subscribe
V530s-07icb Firmware Subscribe
V530s-07icr Subscribe
V530s-07icr Firmware Subscribe
V540-24iwl Subscribe
V540-24iwl Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-34069 A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-77639.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:16:04.358Z

Reserved: 2022-01-24T00:00:00

Link: CVE-2021-4211

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-22T21:15:10.007

Modified: 2024-11-21T06:37:09.520

Link: CVE-2021-4211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses