Description
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
Published: 2022-04-22
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-84943.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-24450 During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
History

No history.

Subscriptions

Lenovo Thinkpad 11e Thinkpad 11e Firmware Thinkpad 11e Yoga Thinkpad 11e Yoga Firmware Thinkpad Helix Thinkpad Helix Firmware Thinkpad L560 Thinkpad L560 Firmware Thinkpad L570 Thinkpad L570 Firmware Thinkpad P50s Thinkpad P50s Firmware Thinkpad P51s Thinkpad P51s Firmware Thinkpad P52s Thinkpad P52s Firmware Thinkpad S540 Thinkpad S540 Firmware Thinkpad T550 Thinkpad T550 Firmware Thinkpad T560 Thinkpad T560 Firmware Thinkpad T570 Thinkpad T570 Firmware Thinkpad T580 Thinkpad T580 Firmware Thinkpad W540 Thinkpad W540 Firmware Thinkpad W541 Thinkpad W541 Firmware Thinkpad W550s Thinkpad W550s Firmware Thinkpad X1 Carbon 3rd Gen Thinkpad X1 Carbon 3rd Gen Firmware Thinkpad X1 Carbon 4th Gen Thinkpad X1 Carbon 4th Gen Firmware Thinkpad X1 Carbon 5th Gen Kabylake Thinkpad X1 Carbon 5th Gen Kabylake Firmware Thinkpad X1 Carbon 5th Gen Skylake Thinkpad X1 Carbon 5th Gen Skylake Firmware Thinkpad X1 Tablet Gen 1 Thinkpad X1 Tablet Gen 1 Firmware Thinkpad X1 Tablet Gen 2 Thinkpad X1 Tablet Gen 2 Firmware Thinkpad X1 Yoga Thinkpad X1 Yoga Firmware Thinkpad X1 Yoga Gen 2 Thinkpad X1 Yoga Gen 2 Firmware Thinkpad X1 Yoga Gen 3 Thinkpad X1 Yoga Gen 3 Firmware Thinkpad X250 Thinkpad X250 Firmware Thinkpad X280 Thinkpad X280 Firmware Thinkpad X390 Thinkpad X390 Firmware Thinkpad Yoga 15 Thinkpad Yoga 15 Firmware Thinkpad Yoga 260 Thinkpad Yoga 260 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-02T23:55:24.201Z

Reserved: 2022-03-27T00:00:00.000Z

Link: CVE-2022-1107

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-22T21:15:10.300

Modified: 2024-11-21T06:40:03.013

Link: CVE-2022-1107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses