A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

Project Subscriptions

Vendors Products
13w Yoga Subscribe
13w Yoga Firmware Subscribe
13w Yoga Gen 2 Subscribe
13w Yoga Gen 2 Firmware Subscribe
Flex 5-14alc05 Subscribe
Flex 5-14alc05 Firmware Subscribe
Flex 5-14are05 Subscribe
Flex 5-14are05 Firmware Subscribe
Flex 5-14iil05 Subscribe
Flex 5-14iil05 Firmware Subscribe
Flex 5-14itl05 Subscribe
Flex 5-14itl05 Firmware Subscribe
Flex 5-15alc05 Subscribe
Flex 5-15alc05 Firmware Subscribe
Flex 5-15iil05 Subscribe
Flex 5-15iil05 Firmware Subscribe
Flex 5-15itl05 Subscribe
Flex 5-15itl05 Firmware Subscribe
Flex 7 14iau7 Firmware Subscribe
Flex 7 14iru8 Subscribe
Flex 7 14iru8 Firmware Subscribe
Ideapad 1-11ada05 Subscribe
Ideapad 1-11ada05 Firmware Subscribe
Ideapad 1-11igl05 Subscribe
Ideapad 1-11igl05 Firmware Subscribe
Ideapad 1-14ada05 Subscribe
Ideapad 1-14ada05 Firmware Subscribe
Ideapad 1-14igl05 Subscribe
Ideapad 1-14igl05 Firmware Subscribe
Ideapad 5-14alc05 Subscribe
Ideapad 5-15alc05 Subscribe
Ideapad Flex 5 14abr8 Subscribe
Ideapad Flex 5 14abr8 Firmware Subscribe
Ideapad Flex 5 14alc7 Subscribe
Ideapad Flex 5 14alc7 Firmware Subscribe
Ideapad Flex 5 14iau7 Subscribe
Ideapad Flex 5 14iau7 Firmware Subscribe
Ideapad Flex 5 14iru8 Subscribe
Ideapad Flex 5 14iru8 Firmware Subscribe
Ideapad Flex 5 16abr8 Subscribe
Ideapad Flex 5 16abr8 Firmware Subscribe
Ideapad Flex 5 16alc7 Subscribe
Ideapad Flex 5 16alc7 Firmware Subscribe
Ideapad Flex 5 16iau7 Subscribe
Ideapad Flex 5 16iau7 Firmware Subscribe
Ideapad Flex 5 16iru8 Subscribe
Ideapad Flex 5 16iru8 Firmware Subscribe
Thinkbook 13s G2 Are Subscribe
Thinkbook 13s G2 Are Firmware Subscribe
Thinkbook 13s G2 Itl Subscribe
Thinkbook 13s G2 Itl Firmware Subscribe
Thinkbook 13s G3 Acn Subscribe
Thinkbook 13s G3 Acn Firmware Subscribe
Thinkbook 13s G4 Iap Subscribe
Thinkbook 13s G4 Iap Firmware Subscribe
Thinkbook 13x G2 Iap Subscribe
Thinkbook 13x G2 Iap Firmware Subscribe
Thinkbook 14s G2 Itl Subscribe
Thinkbook 14s G2 Itl Firmware Subscribe
Yoga 9-15imh5 Subscribe
Yoga 9-15imh5 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-53921 A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-134879.


Workaround

No workaround given by the vendor.

History

Tue, 08 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Lenovo flex 7 14iau7 Firmware
Lenovo ideapad 5-14alc05
Lenovo ideapad 5-15alc05
CPEs cpe:2.3:h:lenovo:ideapad_5-14alc05:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:ideapad_5-15alc05:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:flex_7_14iau7_firmware:*:*:*:*:*:*:*:*
Vendors & Products Lenovo flex 7 14iau7 Firmware
Lenovo ideapad 5-14alc05
Lenovo ideapad 5-15alc05
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-10-08T13:50:36.650Z

Reserved: 2023-07-31T16:44:11.696Z

Link: CVE-2023-4028

cve-icon Vulnrichment

Updated: 2024-08-02T07:17:11.498Z

cve-icon NVD

Status : Modified

Published: 2023-08-17T17:15:10.217

Modified: 2024-11-21T08:34:15.500

Link: CVE-2023-4028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses