A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Project Subscriptions

Vendors Products
C340-14iml Subscribe
C340-14iml Firmware Subscribe
C340-15iml Subscribe
C340-15iml Firmware Subscribe
D330-10igm Subscribe
D330-10igm Firmware Subscribe
Duet 3-10igl5 Subscribe
Duet 3-10igl5 Firmware Subscribe
E41-50 Firmware Subscribe
Flex-14iml Subscribe
Flex-14iml Firmware Subscribe
Flex-15iml Subscribe
Flex-15iml Firmware Subscribe
Ideapad 3-14are05 Subscribe
Ideapad 3-14are05 Firmware Subscribe
Ideapad 3-15are05 Subscribe
Ideapad 3-15are05 Firmware Subscribe
Ideapad 3-17are05 Subscribe
Ideapad 3-17are05 Firmware Subscribe
Ideapad 5-14alc05 Subscribe
Ideapad 5-14alc05 Firmware Subscribe
Ideapad 5-14are05 Subscribe
Ideapad 5-14are05 Firmware Subscribe
Ideapad 5-15itl05 Subscribe
Ideapad 5-15itl05 Firmware Subscribe
Ideapad 5 Pro-14acn6 Subscribe
Ideapad 5 Pro-14acn6 Firmware Subscribe
Ideapad 5 Pro-14itl6 Subscribe
Ideapad 5 Pro-14itl6 Firmware Subscribe
Ideapad 5 Pro-16ihu6 Subscribe
Ideapad 5 Pro-16ihu6 Firmware Subscribe
Ideapad Creator 5-15imh05 Subscribe
Ideapad Creator 5-15imh05 Firmware Subscribe
Ideapad Gaming 3-15ach6 Subscribe
Ideapad Gaming 3-15ach6 Firmware Subscribe
Ideapad Gaming 3-15arh05 Subscribe
Ideapad Gaming 3-15arh05 Firmware Subscribe
Ideapad Gaming 3-15imh05 Subscribe
Ideapad Gaming 3-15imh05 Firmware Subscribe
L340-15irh Subscribe
L340-15irh Firmware Subscribe
L340-15iwl Subscribe
L340-15iwl Firmware Subscribe
L340-15iwl Touch Subscribe
L340-15iwl Touch Firmware Subscribe
L340-17irh Subscribe
L340-17irh Firmware Subscribe
L340-17iwl Subscribe
L340-17iwl Firmware Subscribe
Legion Y540-15irh Subscribe
Legion Y540-15irh-pg0 Subscribe
Legion Y540-15irh-pg0 Firmware Subscribe
Legion Y540-15irh Firmware Subscribe
Legion Y540-17irh Subscribe
Legion Y540-17irh-pg0 Subscribe
Legion Y540-17irh-pg0 Firmware Subscribe
Legion Y540-17irh Firmware Subscribe
Legion Y545 Subscribe
Legion Y545-pg0 Subscribe
Legion Y545-pg0 Firmware Subscribe
Legion Y545 Firmware Subscribe
Legion Y7000-2019 Subscribe
Legion Y7000-2019-pg0 Subscribe
Legion Y7000-2019-pg0 Firmware Subscribe
Legion Y7000-2019 Firmware Subscribe
S340-13iml Subscribe
S340-13iml Firmware Subscribe
S340-14api Subscribe
S340-14api Firmware Subscribe
S340-14iml Subscribe
S340-14iml Firmware Subscribe
S340-15api Subscribe
S340-15api Firmware Subscribe
S340-15api Touch Subscribe
S340-15api Touch Firmware Subscribe
S340-15iml Subscribe
S340-15iml Firmware Subscribe
S540-14iml Subscribe
S540-14iml Firmware Subscribe
S540-14iml Touch Subscribe
S540-14iml Touch Firmware Subscribe
S540-15iml Subscribe
S540-15iml Firmware Subscribe
Slim 7-14are05 Subscribe
Slim 7-14are05 Firmware Subscribe
Slim 7-14itl05 Subscribe
Slim 7-14itl05 Firmware Subscribe
Slim 7-15iil05 Subscribe
Slim 7-15iil05 Firmware Subscribe
Slim 7-15imh05 Subscribe
Slim 7-15imh05 Firmware Subscribe
Slim 7-15itl05 Subscribe
Slim 7-15itl05 Firmware Subscribe
Thinkbook 13x Itg Subscribe
Thinkbook 13x Itg Firmware Subscribe
Thinkbook 14 G3 Itl Subscribe
Thinkbook 14 G3 Itl Firmware Subscribe
Thinkbook Plus G2 Itg Subscribe
Thinkbook Plus G2 Itg Firmware Subscribe
V14-are Subscribe
V14-are Firmware Subscribe
V140-15iwl Subscribe
V140-15iwl Firmware Subscribe
V340-17iwl Subscribe
V340-17iwl Firmware Subscribe
Yoga 6-13alc6 Subscribe
Yoga 6-13alc6 Firmware Subscribe
Yoga Creator 7-15imh05 Subscribe
Yoga Creator 7-15imh05 Firmware Subscribe
Yoga Slim 7-14are05 Subscribe
Yoga Slim 7-14are05 Firmware Subscribe
Yoga Slim 7-14iil05 Subscribe
Yoga Slim 7-14iil05 Firmware Subscribe
Yoga Slim 7-14itl05 Subscribe
Yoga Slim 7-14itl05 Firmware Subscribe
Yoga Slim 7-15iil05 Subscribe
Yoga Slim 7-15iil05 Firmware Subscribe
Yoga Slim 7-15imh05 Subscribe
Yoga Slim 7-15imh05 Firmware Subscribe
Yoga Slim 7-15itl05 Subscribe
Yoga Slim 7-15itl05 Firmware Subscribe
Yoga Slim 7 Carbon 13itl5 Subscribe
Yoga Slim 7 Carbon 13itl5 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-34070 A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-77639.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:16:04.273Z

Reserved: 2022-01-24T00:00:00

Link: CVE-2021-4212

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-22T21:15:10.067

Modified: 2024-11-21T06:37:09.727

Link: CVE-2021-4212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses