Description
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
Published: 2023-06-05
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the related Lenovo advisory:  https://support.lenovo.com/us/en/product_security/LEN-124495 https://support.lenovo.com/us/en/product_security/LEN-124495

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-50899 A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
History

Wed, 08 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Lenovo Ideacentre 510s-07icb Ideacentre 510s-07icb Firmware Ideacentre 510s-07ick Ideacentre 510s-07ick Firmware Ideacentre 720-18apr Ideacentre 720-18apr Firmware Ideacentre Aio 3-22itl6 Ideacentre Aio 3-22itl6 Firmware Ideacentre Aio 3-24itl6 Ideacentre Aio 3-24itl6 Firmware Ideacentre Aio 3-27itl6 Ideacentre Aio 3-27itl6 Firmware Ideacentre Aio 3 21itl7 Ideacentre Aio 3 21itl7 Firmware Thinkcentre M720e Thinkcentre M720e Firmware Thinkcentre M720q Thinkcentre M720q Firmware Thinkcentre M720s Thinkcentre M720s Firmware Thinkcentre M720t Thinkcentre M720t Firmware Thinkcentre M725s Thinkcentre M725s Firmware Thinkcentre M75s Gen 2 Thinkcentre M75s Gen 2 Firmware Thinkcentre M75t Gen 2 Thinkcentre M75t Gen 2 Firmware Thinkcentre M920q Thinkcentre M920q Firmware Thinkcentre M920s Thinkcentre M920s Firmware Thinkcentre M920t Thinkcentre M920t Firmware Thinkcentre M920x Thinkcentre M920x Firmware Thinkcentre M920z Thinkcentre M920z Firmware Thinkstation P330 Tiny Thinkstation P330 Tiny Firmware Thinkstation P360 Ultra Thinkstation P360 Ultra Firmware Thinkstation P520 Thinkstation P520 Firmware Thinkstation P520c Thinkstation P520c Firmware V30a-22itl V30a-22itl Firmware V30a-24itl V30a-24itl Firmware V530s-07icb V530s-07icb Firmware V530s-07icr V530s-07icr Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-01-08T15:50:42.163Z

Reserved: 2022-12-29T17:29:25.496Z

Link: CVE-2022-48188

cve-icon Vulnrichment

Updated: 2024-08-03T15:10:58.423Z

cve-icon NVD

Status : Modified

Published: 2023-06-05T22:15:11.563

Modified: 2024-11-21T07:32:56.600

Link: CVE-2022-48188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses