Description
A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.
No analysis available yet.
Remediation
Vendor Solution
Update system firmware to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-141775
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29448 | A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-141775 |
|
History
Mon, 16 Sep 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 |
Mon, 16 Sep 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code. | A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code. |
| Weaknesses | CWE-306 |
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-16T14:50:40.027Z
Reserved: 2023-02-06T15:09:03.709Z
Link: CVE-2023-25493
Updated: 2024-08-02T11:25:18.371Z
Status : Deferred
Published: 2024-04-05T21:15:07.607
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-25493
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:21:45Z
Weaknesses
EUVD