A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.

Project Subscriptions

Vendors Products
Ideacentre 510s-07icb Subscribe
Ideacentre 510s-07icb Firmware Subscribe
Ideacentre 510s-07ick Subscribe
Ideacentre 510s-07ick Firmware Subscribe
Ideacentre 720-18apr Subscribe
Ideacentre 720-18apr Firmware Subscribe
Ideacentre Aio 3-22itl6 Subscribe
Ideacentre Aio 3-22itl6 Firmware Subscribe
Ideacentre Aio 3-24itl6 Subscribe
Ideacentre Aio 3-24itl6 Firmware Subscribe
Ideacentre Aio 3-27itl6 Subscribe
Ideacentre Aio 3-27itl6 Firmware Subscribe
Ideacentre Aio 3 21itl7 Subscribe
Ideacentre Aio 3 21itl7 Firmware Subscribe
Thinkcentre M720e Subscribe
Thinkcentre M720e Firmware Subscribe
Thinkcentre M720q Subscribe
Thinkcentre M720q Firmware Subscribe
Thinkcentre M720s Subscribe
Thinkcentre M720s Firmware Subscribe
Thinkcentre M720t Subscribe
Thinkcentre M720t Firmware Subscribe
Thinkcentre M725s Subscribe
Thinkcentre M725s Firmware Subscribe
Thinkcentre M75s Gen 2 Subscribe
Thinkcentre M75s Gen 2 Firmware Subscribe
Thinkcentre M75t Gen 2 Subscribe
Thinkcentre M75t Gen 2 Firmware Subscribe
Thinkcentre M920q Subscribe
Thinkcentre M920q Firmware Subscribe
Thinkcentre M920s Subscribe
Thinkcentre M920s Firmware Subscribe
Thinkcentre M920t Subscribe
Thinkcentre M920t Firmware Subscribe
Thinkcentre M920x Subscribe
Thinkcentre M920x Firmware Subscribe
Thinkcentre M920z Subscribe
Thinkcentre M920z Firmware Subscribe
Thinkstation P330 Tiny Subscribe
Thinkstation P330 Tiny Firmware Subscribe
Thinkstation P360 Ultra Subscribe
Thinkstation P360 Ultra Firmware Subscribe
Thinkstation P520 Subscribe
Thinkstation P520 Firmware Subscribe
Thinkstation P520c Subscribe
Thinkstation P520c Firmware Subscribe
V30a-22itl Subscribe
V30a-22itl Firmware Subscribe
V30a-24itl Subscribe
V30a-24itl Firmware Subscribe
V530s-07icb Subscribe
V530s-07icb Firmware Subscribe
V530s-07icr Subscribe
V530s-07icr Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-50899 A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the related Lenovo advisory:  https://support.lenovo.com/us/en/product_security/LEN-124495 https://support.lenovo.com/us/en/product_security/LEN-124495


Workaround

No workaround given by the vendor.

History

Wed, 08 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-01-08T15:50:42.163Z

Reserved: 2022-12-29T17:29:25.496Z

Link: CVE-2022-48188

cve-icon Vulnrichment

Updated: 2024-08-03T15:10:58.423Z

cve-icon NVD

Status : Modified

Published: 2023-06-05T22:15:11.563

Modified: 2024-11-21T07:32:56.600

Link: CVE-2022-48188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses