Description
A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
Published: 2023-08-17
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-134879.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-53921 A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
History

Tue, 08 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Lenovo flex 7 14iau7 Firmware
Lenovo ideapad 5-14alc05
Lenovo ideapad 5-15alc05
CPEs cpe:2.3:h:lenovo:ideapad_5-14alc05:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:ideapad_5-15alc05:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:flex_7_14iau7_firmware:*:*:*:*:*:*:*:*
Vendors & Products Lenovo flex 7 14iau7 Firmware
Lenovo ideapad 5-14alc05
Lenovo ideapad 5-15alc05
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Lenovo 13w Yoga 13w Yoga Firmware 13w Yoga Gen 2 13w Yoga Gen 2 Firmware Flex 5-14alc05 Flex 5-14alc05 Firmware Flex 5-14are05 Flex 5-14are05 Firmware Flex 5-14iil05 Flex 5-14iil05 Firmware Flex 5-14itl05 Flex 5-14itl05 Firmware Flex 5-15alc05 Flex 5-15alc05 Firmware Flex 5-15iil05 Flex 5-15iil05 Firmware Flex 5-15itl05 Flex 5-15itl05 Firmware Flex 7 14iau7 Firmware Flex 7 14iru8 Flex 7 14iru8 Firmware Ideapad 1-11ada05 Ideapad 1-11ada05 Firmware Ideapad 1-11igl05 Ideapad 1-11igl05 Firmware Ideapad 1-14ada05 Ideapad 1-14ada05 Firmware Ideapad 1-14igl05 Ideapad 1-14igl05 Firmware Ideapad 5-14alc05 Ideapad 5-15alc05 Ideapad Flex 5 14abr8 Ideapad Flex 5 14abr8 Firmware Ideapad Flex 5 14alc7 Ideapad Flex 5 14alc7 Firmware Ideapad Flex 5 14iau7 Ideapad Flex 5 14iau7 Firmware Ideapad Flex 5 14iru8 Ideapad Flex 5 14iru8 Firmware Ideapad Flex 5 16abr8 Ideapad Flex 5 16abr8 Firmware Ideapad Flex 5 16alc7 Ideapad Flex 5 16alc7 Firmware Ideapad Flex 5 16iau7 Ideapad Flex 5 16iau7 Firmware Ideapad Flex 5 16iru8 Ideapad Flex 5 16iru8 Firmware Thinkbook 13s G2 Are Thinkbook 13s G2 Are Firmware Thinkbook 13s G2 Itl Thinkbook 13s G2 Itl Firmware Thinkbook 13s G3 Acn Thinkbook 13s G3 Acn Firmware Thinkbook 13s G4 Iap Thinkbook 13s G4 Iap Firmware Thinkbook 13x G2 Iap Thinkbook 13x G2 Iap Firmware Thinkbook 14s G2 Itl Thinkbook 14s G2 Itl Firmware Yoga 9-15imh5 Yoga 9-15imh5 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-10-08T13:50:36.650Z

Reserved: 2023-07-31T16:44:11.696Z

Link: CVE-2023-4028

cve-icon Vulnrichment

Updated: 2024-08-02T07:17:11.498Z

cve-icon NVD

Status : Modified

Published: 2023-08-17T17:15:10.217

Modified: 2024-11-21T08:34:15.500

Link: CVE-2023-4028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses