Metrics
No CVSS v4.0
Attack Vector Local
Attack Complexity Low
Privileges Required High
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
This CVE is not in the KEV list.
The EPSS score is 0.00032.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Thinkpad 11e
Subscribe
Thinkpad 11e Firmware
Subscribe
Thinkpad 11e Yoga
Subscribe
Thinkpad 11e Yoga Firmware
Subscribe
Thinkpad Helix
Subscribe
Thinkpad Helix Firmware
Subscribe
Thinkpad L560
Subscribe
Thinkpad L560 Firmware
Subscribe
Thinkpad L570
Subscribe
Thinkpad L570 Firmware
Subscribe
Thinkpad P50s
Subscribe
Thinkpad P50s Firmware
Subscribe
Thinkpad P51s
Subscribe
Thinkpad P51s Firmware
Subscribe
Thinkpad P52s
Subscribe
Thinkpad P52s Firmware
Subscribe
Thinkpad S540
Subscribe
Thinkpad S540 Firmware
Subscribe
Thinkpad T550
Subscribe
Thinkpad T550 Firmware
Subscribe
Thinkpad T560
Subscribe
Thinkpad T560 Firmware
Subscribe
Thinkpad T570
Subscribe
Thinkpad T570 Firmware
Subscribe
Thinkpad T580
Subscribe
Thinkpad T580 Firmware
Subscribe
Thinkpad W540
Subscribe
Thinkpad W540 Firmware
Subscribe
Thinkpad W541
Subscribe
Thinkpad W541 Firmware
Subscribe
Thinkpad W550s
Subscribe
Thinkpad W550s Firmware
Subscribe
Thinkpad X1 Carbon 3rd Gen
Subscribe
Thinkpad X1 Carbon 3rd Gen Firmware
Subscribe
Thinkpad X1 Carbon 4th Gen
Subscribe
Thinkpad X1 Carbon 4th Gen Firmware
Subscribe
Thinkpad X1 Carbon 5th Gen Kabylake
Subscribe
Thinkpad X1 Carbon 5th Gen Kabylake Firmware
Subscribe
Thinkpad X1 Carbon 5th Gen Skylake
Subscribe
Thinkpad X1 Carbon 5th Gen Skylake Firmware
Subscribe
Thinkpad X1 Tablet Gen 1
Subscribe
Thinkpad X1 Tablet Gen 1 Firmware
Subscribe
Thinkpad X1 Tablet Gen 2
Subscribe
Thinkpad X1 Tablet Gen 2 Firmware
Subscribe
Thinkpad X1 Yoga
Subscribe
Thinkpad X1 Yoga Firmware
Subscribe
Thinkpad X1 Yoga Gen 2
Subscribe
Thinkpad X1 Yoga Gen 2 Firmware
Subscribe
Thinkpad X1 Yoga Gen 3
Subscribe
Thinkpad X1 Yoga Gen 3 Firmware
Subscribe
Thinkpad X250
Subscribe
Thinkpad X250 Firmware
Subscribe
Thinkpad X280
Subscribe
Thinkpad X280 Firmware
Subscribe
Thinkpad X390
Subscribe
Thinkpad X390 Firmware
Subscribe
Thinkpad Yoga 15
Subscribe
Thinkpad Yoga 15 Firmware
Subscribe
Thinkpad Yoga 260
Subscribe
Thinkpad Yoga 260 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
Configuration 26 [-]
| AND |
|
Configuration 27 [-]
| AND |
|
Configuration 28 [-]
| AND |
|
Configuration 29 [-]
| AND |
|
Configuration 30 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24450 | During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code. |
Solution
Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-84943.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-84943 |
|
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-02T23:55:24.201Z
Reserved: 2022-03-27T00:00:00
Link: CVE-2022-1107
No data.
Status : Modified
Published: 2022-04-22T21:15:10.300
Modified: 2024-11-21T06:40:03.013
Link: CVE-2022-1107
No data.
OpenCVE Enrichment
No data.
EUVD