Description
A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Published: 2022-04-22
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-77639.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-34070 A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.
History

No history.

Subscriptions

Lenovo C340-14iml C340-14iml Firmware C340-15iml C340-15iml Firmware D330-10igm D330-10igm Firmware Duet 3-10igl5 Duet 3-10igl5 Firmware E41-50 E41-50 Firmware Flex-14iml Flex-14iml Firmware Flex-15iml Flex-15iml Firmware Ideapad 3-14are05 Ideapad 3-14are05 Firmware Ideapad 3-15are05 Ideapad 3-15are05 Firmware Ideapad 3-17are05 Ideapad 3-17are05 Firmware Ideapad 5-14alc05 Ideapad 5-14alc05 Firmware Ideapad 5-14are05 Ideapad 5-14are05 Firmware Ideapad 5-15itl05 Ideapad 5-15itl05 Firmware Ideapad 5 Pro-14acn6 Ideapad 5 Pro-14acn6 Firmware Ideapad 5 Pro-14itl6 Ideapad 5 Pro-14itl6 Firmware Ideapad 5 Pro-16ihu6 Ideapad 5 Pro-16ihu6 Firmware Ideapad Creator 5-15imh05 Ideapad Creator 5-15imh05 Firmware Ideapad Gaming 3-15ach6 Ideapad Gaming 3-15ach6 Firmware Ideapad Gaming 3-15arh05 Ideapad Gaming 3-15arh05 Firmware Ideapad Gaming 3-15imh05 Ideapad Gaming 3-15imh05 Firmware L340-15irh L340-15irh Firmware L340-15iwl L340-15iwl Firmware L340-15iwl Touch L340-15iwl Touch Firmware L340-17irh L340-17irh Firmware L340-17iwl L340-17iwl Firmware Legion Y540-15irh Legion Y540-15irh-pg0 Legion Y540-15irh-pg0 Firmware Legion Y540-15irh Firmware Legion Y540-17irh Legion Y540-17irh-pg0 Legion Y540-17irh-pg0 Firmware Legion Y540-17irh Firmware Legion Y545 Legion Y545-pg0 Legion Y545-pg0 Firmware Legion Y545 Firmware Legion Y7000-2019 Legion Y7000-2019-pg0 Legion Y7000-2019-pg0 Firmware Legion Y7000-2019 Firmware S340-13iml S340-13iml Firmware S340-14api S340-14api Firmware S340-14iml S340-14iml Firmware S340-15api S340-15api Firmware S340-15api Touch S340-15api Touch Firmware S340-15iml S340-15iml Firmware S540-14iml S540-14iml Firmware S540-14iml Touch S540-14iml Touch Firmware S540-15iml S540-15iml Firmware Slim 7-14are05 Slim 7-14are05 Firmware Slim 7-14itl05 Slim 7-14itl05 Firmware Slim 7-15iil05 Slim 7-15iil05 Firmware Slim 7-15imh05 Slim 7-15imh05 Firmware Slim 7-15itl05 Slim 7-15itl05 Firmware Thinkbook 13x Itg Thinkbook 13x Itg Firmware Thinkbook 14 G3 Itl Thinkbook 14 G3 Itl Firmware Thinkbook Plus G2 Itg Thinkbook Plus G2 Itg Firmware V14-are V14-are Firmware V140-15iwl V140-15iwl Firmware V340-17iwl V340-17iwl Firmware Yoga 6-13alc6 Yoga 6-13alc6 Firmware Yoga Creator 7-15imh05 Yoga Creator 7-15imh05 Firmware Yoga Slim 7-14are05 Yoga Slim 7-14are05 Firmware Yoga Slim 7-14iil05 Yoga Slim 7-14iil05 Firmware Yoga Slim 7-14itl05 Yoga Slim 7-14itl05 Firmware Yoga Slim 7-15iil05 Yoga Slim 7-15iil05 Firmware Yoga Slim 7-15imh05 Yoga Slim 7-15imh05 Firmware Yoga Slim 7-15itl05 Yoga Slim 7-15itl05 Firmware Yoga Slim 7 Carbon 13itl5 Yoga Slim 7 Carbon 13itl5 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:16:04.273Z

Reserved: 2022-01-24T00:00:00.000Z

Link: CVE-2021-4212

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-22T21:15:10.067

Modified: 2024-11-21T06:37:09.727

Link: CVE-2021-4212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses