Metrics
No CVSS v4.0
Attack Vector Local
Attack Complexity Low
Privileges Required High
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
The EPSS score is 0.00037.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Legion 5-15ach6
Subscribe
Legion 5-15ach6 Firmware
Subscribe
Legion 5-15ach6a
Subscribe
Legion 5-15ach6a Firmware
Subscribe
Legion 5-15ach6h
Subscribe
Legion 5-15ach6h Firmware
Subscribe
Legion 5-15ith6
Subscribe
Legion 5-15ith6 Firmware
Subscribe
Legion 5-15ith6h
Subscribe
Legion 5-15ith6h Firmware
Subscribe
Legion 5-17ach6
Subscribe
Legion 5-17ach6 Firmware
Subscribe
Legion 5-17ach6h
Subscribe
Legion 5-17ach6h Firmware
Subscribe
Legion 5-17ith6
Subscribe
Legion 5-17ith6 Firmware
Subscribe
Legion 5-17ith6h
Subscribe
Legion 5-17ith6h Firmware
Subscribe
Legion 5 15arh7
Subscribe
Legion 5 15arh7 Firmware
Subscribe
Legion 5 15arh7h
Subscribe
Legion 5 15arh7h Firmware
Subscribe
Legion 5 15iah7
Subscribe
Legion 5 15iah7 Firmware
Subscribe
Legion 5 15iah7h
Subscribe
Legion 5 15iah7h Firmware
Subscribe
Legion 5 Pro-16ach6
Subscribe
Legion 5 Pro-16ach6 Firmware
Subscribe
Legion 5 Pro-16ach6h
Subscribe
Legion 5 Pro-16ach6h Firmware
Subscribe
Legion 5 Pro-16ith6
Subscribe
Legion 5 Pro-16ith6 Firmware
Subscribe
Legion 5 Pro-16ith6h
Subscribe
Legion 5 Pro-16ith6h Firmware
Subscribe
Legion 5 Pro 16arh7
Subscribe
Legion 5 Pro 16arh7 Firmware
Subscribe
Legion 5 Pro 16arh7h
Subscribe
Legion 5 Pro 16arh7h Firmware
Subscribe
Legion 5 Pro 16iah7
Subscribe
Legion 5 Pro 16iah7 Firmware
Subscribe
Legion 5 Pro 16iah7h
Subscribe
Legion 5 Pro 16iah7h Firmware
Subscribe
Legion 7-16achg6
Subscribe
Legion 7-16achg6 Firmware
Subscribe
Legion 7-16arha7
Subscribe
Legion 7-16arha7 Firmware
Subscribe
Legion 7-16ithg6
Subscribe
Legion 7-16ithg6 Firmware
Subscribe
Legion Pro 5 16irx8
Subscribe
Legion Pro 5 16irx8 Firmware
Subscribe
Legion Pro 7 16irx8
Subscribe
Legion Pro 7 16irx8 Firmware
Subscribe
Legion Pro 7 16irx8h
Subscribe
Legion Pro 7 16irx8h Firmware
Subscribe
Legion S7 16arha7
Subscribe
Legion S7 16arha7 Firmware
Subscribe
Thinkbook 15p G2 Ith
Subscribe
Thinkbook 15p G2 Ith Firmware
Subscribe
Thinkbook 16p G3 Arh
Subscribe
Thinkbook 16p G3 Arh Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
Configuration 26 [-]
| AND |
|
Configuration 27 [-]
| AND |
|
Configuration 28 [-]
| AND |
|
Configuration 29 [-]
| AND |
|
Configuration 30 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-38496 | A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. |
Solution
Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-134879.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-134879 |
|
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-02T16:10:06.823Z
Reserved: 2023-06-05T19:15:31.605Z
Link: CVE-2023-34419
No data.
Status : Modified
Published: 2023-08-17T17:15:09.913
Modified: 2024-11-21T08:07:12.007
Link: CVE-2023-34419
No data.
OpenCVE Enrichment
No data.
EUVD