Description

An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.  

Published: 2023-10-30
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-106014.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-51907 An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.  
History

No history.

Subscriptions

Lenovo Thinkpad L14 Thinkpad L14 Firmware Thinkpad L14 Gen 2 Thinkpad L14 Gen 2 Firmware Thinkpad L15 Thinkpad L15 Firmware Thinkpad L15 Gen 2 Thinkpad L15 Gen 2 Firmware Thinkpad P14s Gen 1 Thinkpad P14s Gen 1 Firmware Thinkpad P14s Gen 2 Thinkpad P14s Gen 2 Firmware Thinkpad P14s Gen 3 Thinkpad P14s Gen 3 Firmware Thinkpad P15 Gen 1 Thinkpad P15 Gen 1 Firmware Thinkpad P15 Gen 2 Thinkpad P15 Gen 2 Firmware Thinkpad P15s Gen 1 Thinkpad P15s Gen 1 Firmware Thinkpad P15s Gen 2 Thinkpad P15s Gen 2 Firmware Thinkpad P15v Gen 1 Thinkpad P15v Gen 1 Firmware Thinkpad P15v Gen 2 Thinkpad P15v Gen 2 Firmware Thinkpad P15v Gen 3 Thinkpad P15v Gen 3 Firmware Thinkpad P16 Gen 1 Thinkpad P16 Gen 1 Firmware Thinkpad P16s Gen 1 Thinkpad P16s Gen 1 Firmware Thinkpad P17 Gen 1 Thinkpad P17 Gen 1 Firmware Thinkpad P17 Gen 2 Thinkpad P17 Gen 2 Firmware Thinkpad P1 Gen 3 Thinkpad P1 Gen 3 Firmware Thinkpad P1 Gen 4 Thinkpad P1 Gen 4 Firmware Thinkpad P1 Gen 5 Thinkpad P1 Gen 5 Firmware Thinkpad T14 Gen 1 Thinkpad T14 Gen 1 Firmware Thinkpad T14 Gen 2 Thinkpad T14 Gen 2 Firmware Thinkpad T14 Gen 3 Thinkpad T14 Gen 3 Firmware Thinkpad T14s Thinkpad T14s Firmware Thinkpad T14s Gen 2 Thinkpad T14s Gen 2 Firmware Thinkpad T14s Gen 3 Thinkpad T14s Gen 3 Firmware Thinkpad T15 Gen 2 Thinkpad T15 Gen 2 Firmware Thinkpad T15g Gen 1 Thinkpad T15g Gen 1 Firmware Thinkpad T15g Gen 2 Thinkpad T15g Gen 2 Firmware Thinkpad T15p Gen 1 Thinkpad T15p Gen 1 Firmware Thinkpad T15p Gen 2 Thinkpad T15p Gen 2 Firmware Thinkpad T15p Gen 3 Thinkpad T15p Gen 3 Firmware Thinkpad T16 Gen 1 Thinkpad T16 Gen 1 Firmware Thinkpad X13 Thinkpad X13 Firmware Thinkpad X13 Gen 2 Thinkpad X13 Gen 2 Firmware Thinkpad X13 Gen 3 Thinkpad X13 Gen 3 Firmware Thinkpad X13 Yoga Gen 1 Thinkpad X13 Yoga Gen 1 Firmware Thinkpad X13 Yoga Gen 2 Thinkpad X13 Yoga Gen 2 Firmware Thinkpad X1 Carbon 10th Gen Thinkpad X1 Carbon 10th Gen Firmware Thinkpad X1 Carbon 7th Gen Thinkpad X1 Carbon 7th Gen Firmware Thinkpad X1 Carbon 8th Gen Thinkpad X1 Carbon 8th Gen Firmware Thinkpad X1 Carbon 9th Gen Thinkpad X1 Carbon 9th Gen Firmware Thinkpad X1 Extreme 3rd Gen Thinkpad X1 Extreme 3rd Gen Firmware Thinkpad X1 Extreme 4th Gen Thinkpad X1 Extreme 4th Gen Firmware Thinkpad X1 Extreme Gen 5 Thinkpad X1 Extreme Gen 5 Firmware Thinkpad X1 Fold Gen 1 Thinkpad X1 Fold Gen 1 Firmware Thinkpad X1 Nano Gen 1 Thinkpad X1 Nano Gen 1 Firmware Thinkpad X1 Nano Gen 2 Thinkpad X1 Nano Gen 2 Firmware Thinkpad X1 Titanium Thinkpad X1 Titanium Firmware Thinkpad X1 Yoga 4th Gen Thinkpad X1 Yoga 4th Gen Firmware Thinkpad X1 Yoga 5th Gen Thinkpad X1 Yoga 5th Gen Firmware Thinkpad X1 Yoga 6th Gen Thinkpad X1 Yoga 6th Gen Firmware Thinkpad X1 Yoga 7th Gen Thinkpad X1 Yoga 7th Gen Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-09T16:51:57.365Z

Reserved: 2022-12-16T21:19:30.420Z

Link: CVE-2022-4574

cve-icon Vulnrichment

Updated: 2024-08-03T01:41:45.781Z

cve-icon NVD

Status : Modified

Published: 2023-10-30T15:15:40.080

Modified: 2024-11-21T07:35:31.330

Link: CVE-2022-4574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses