A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.

Project Subscriptions

Vendors Products
Ideapad 1-14ijl7 Subscribe
Ideapad 1-14ijl7 Firmware Subscribe
Ideapad 1-15ijl7 Subscribe
Ideapad 1-15ijl7 Firmware Subscribe
Ideapad 1 14iau7 Subscribe
Ideapad 1 14iau7 Firmware Subscribe
Ideapad 1 14igl7 Subscribe
Ideapad 1 14igl7 Firmware Subscribe
Ideapad 1 15iau7 Subscribe
Ideapad 1 15iau7 Firmware Subscribe
Ideapad 1 15igl7 Subscribe
Ideapad 1 15igl7 Firmware Subscribe
Ideapad 3-14igl05 Subscribe
Ideapad 3-14igl05 Firmware Subscribe
Ideapad 3-14iil05 Subscribe
Ideapad 3-14iil05 Firmware Subscribe
Ideapad 3-14iml05 Subscribe
Ideapad 3-14iml05 Firmware Subscribe
Ideapad 3-14itl05 Subscribe
Ideapad 3-14itl05 Firmware Subscribe
Ideapad 3-14itl6 Subscribe
Ideapad 3-14itl6 Firmware Subscribe
Ideapad 3-15igl05 Subscribe
Ideapad 3-15igl05 Firmware Subscribe
Ideapad 3-15iil05 Subscribe
Ideapad 3-15iil05 Firmware Subscribe
Ideapad 3-15iml05 Subscribe
Ideapad 3-15iml05 Firmware Subscribe
Ideapad 3-15itl05 Subscribe
Ideapad 3-15itl05 Firmware Subscribe
Ideapad 3-15itl6 Subscribe
Ideapad 3-15itl6 Firmware Subscribe
Ideapad 3-17iil05 Subscribe
Ideapad 3-17iil05 Firmware Subscribe
Ideapad 3-17iml05 Subscribe
Ideapad 3-17iml05 Firmware Subscribe
Ideapad 3-17itl6 Subscribe
Ideapad 3-17itl6 Firmware Subscribe
Ideapad 3 14iau7 Subscribe
Ideapad 3 14iau7 Firmware Subscribe
Ideapad 3 15iau7 Subscribe
Ideapad 3 15iau7 Firmware Subscribe
Ideapad 3 17iau7 Subscribe
Ideapad 3 17iau7 Firmware Subscribe
Ideapad 5-15iil05 Subscribe
Ideapad 5-15iil05 Firmware Subscribe
Ideapad 5-15itl05 Subscribe
Ideapad 5-15itl05 Firmware Subscribe
Ideapad 5 15ial7 Subscribe
Ideapad 5 15ial7 Firmware Subscribe
Ideapad Creator 5-15imh05 Subscribe
Ideapad Creator 5-15imh05 Firmware Subscribe
Ideapad Gaming 3-15imh05 Subscribe
Ideapad Gaming 3-15imh05 Firmware Subscribe
L3-15iml05 Subscribe
L3-15iml05 Firmware Subscribe
L3-15itl6 Subscribe
L3-15itl6 Firmware Subscribe
Legion 5-15imh05 Subscribe
Legion 5-15imh05 Firmware Subscribe
Legion 5-15imh05h Subscribe
Legion 5-15imh05h Firmware Subscribe
Legion 5-15imh6 Subscribe
Legion 5-15imh6 Firmware Subscribe
Legion 5-15ith6 Subscribe
Legion 5-15ith6 Firmware Subscribe
Legion 5-15ith6h Subscribe
Legion 5-15ith6h Firmware Subscribe
Legion 5-17imh05 Subscribe
Legion 5-17imh05 Firmware Subscribe
Legion 5-17imh05h Subscribe
Legion 5-17imh05h Firmware Subscribe
Legion 5-17ith6 Subscribe
Legion 5-17ith6 Firmware Subscribe
Legion 5-17ith6h Subscribe
Legion 5-17ith6h Firmware Subscribe
Legion 5 15iah7 Subscribe
Legion 5 15iah7 Firmware Subscribe
Legion 5 15iah7h Subscribe
Legion 5 15iah7h Firmware Subscribe
Legion 5 Pro-16ith6 Subscribe
Legion 5 Pro-16ith6 Firmware Subscribe
Legion 5 Pro-16ith6h Subscribe
Legion 5 Pro-16ith6h Firmware Subscribe
Legion 5 Pro 16iah7 Subscribe
Legion 5 Pro 16iah7 Firmware Subscribe
Legion 5 Pro 16iah7h Subscribe
Legion 5 Pro 16iah7h Firmware Subscribe
Legion 5p-15imh05 Subscribe
Legion 5p-15imh05 Firmware Subscribe
Legion 5p-15imh05h Subscribe
Legion 5p-15imh05h Firmware Subscribe
Legion 7-16ithg6 Subscribe
Legion 7-16ithg6 Firmware Subscribe
Legion 7 16iax7 Subscribe
Legion 7 16iax7 Firmware Subscribe
S14 G2 Itl Subscribe
S14 G2 Itl Firmware Subscribe
S14 G3 Iap Subscribe
S14 G3 Iap Firmware Subscribe
S540-13itl Subscribe
S540-13itl Firmware Subscribe
Slim 7 14iap7 Subscribe
Slim 7 14iap7 Firmware Subscribe
Slim 7 Carbon 13iap7 Subscribe
Slim 7 Carbon 13iap7 Firmware Subscribe
Slim 7 Pro-14ihu5 Subscribe
Slim 7 Pro-14ihu5 Firmware Subscribe
Slim 7 Prox 14iah7 Subscribe
Slim 7 Prox 14iah7 Firmware Subscribe
Slim 9-14itl05 Subscribe
Slim 9-14itl05 Firmware Subscribe
Slim 9 14iap7 Subscribe
Slim 9 14iap7 Firmware Subscribe
Thinkbook 15p G2 Ith Subscribe
Thinkbook 15p G2 Ith Firmware Subscribe
Thinkbook 15p Imh Subscribe
Thinkbook 15p Imh Firmware Subscribe
V14-igl Subscribe
V14-igl Firmware Subscribe
V14 G1-iml Subscribe
V14 G1-iml Firmware Subscribe
V14 G2-itl Subscribe
V14 G2-itl Firmware Subscribe
V14 G2 Ijl Subscribe
V14 G2 Ijl Firmware Subscribe
V14 G3 Iap Subscribe
V14 G3 Iap Firmware Subscribe
V15-igl Subscribe
V15-igl Firmware Subscribe
V15 G1-iml Subscribe
V15 G1-iml Firmware Subscribe
V15 G2-itl Subscribe
V15 G2-itl Firmware Subscribe
V15 G2 Ijl Subscribe
V15 G2 Ijl Firmware Subscribe
V15 G3 Iap Subscribe
V15 G3 Iap Firmware Subscribe
V17-iil Subscribe
V17-iil Firmware Subscribe
V17 G2-itl Subscribe
V17 G2-itl Firmware Subscribe
V17 G3 Iap Subscribe
V17 G3 Iap Firmware Subscribe
Yoga 7-14itl5 Subscribe
Yoga 7-14itl5 Firmware Subscribe
Yoga 7-15itl5 Subscribe
Yoga 7-15itl5 Firmware Subscribe
Yoga 7 14ial7 Subscribe
Yoga 7 14ial7 Firmware Subscribe
Yoga 7 16iah7 Subscribe
Yoga 7 16iah7 Firmware Subscribe
Yoga 7 16iap7 Subscribe
Yoga 7 16iap7 Firmware Subscribe
Yoga 9 14iap7 Subscribe
Yoga 9 14iap7 Firmware Subscribe
Yoga Slim 7 Carbon 13iap7 Subscribe
Yoga Slim 7 Carbon 13iap7 Firmware Subscribe
Yoga Slim 7 Pro-14ihu5 Subscribe
Yoga Slim 7 Pro-14ihu5 Firmware Subscribe
Yoga Slim 7 Pro-14ihu5 O Subscribe
Yoga Slim 7 Pro-14ihu5 O Firmware Subscribe
Yoga Slim 7 Pro-14itl5 Subscribe
Yoga Slim 7 Pro-14itl5 Firmware Subscribe
Yoga Slim 7 Pro 14iah7 Subscribe
Yoga Slim 7 Pro 14iah7 Firmware Subscribe
Yoga Slim 7 Pro 14iap7 Subscribe
Yoga Slim 7 Pro 14iap7 Firmware Subscribe
Yoga Slim 7 Prox 14iah7 Subscribe
Yoga Slim 7 Prox 14iah7 Firmware Subscribe
Yoga Slim 9-14itl05 Subscribe
Yoga Slim 9-14itl05 Firmware Subscribe
Yoga Slim 9 14iap7 Subscribe
Yoga Slim 9 14iap7 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-43100 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-103710.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T01:20:57.610Z

Reserved: 2022-10-28T14:48:18.783Z

Link: CVE-2022-3744

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-08-23T20:15:08.577

Modified: 2024-11-21T07:20:09.543

Link: CVE-2022-3744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses