A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-53922 | A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code. |
Fixes
Solution
Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-134879.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-134879 |
|
History
Tue, 08 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lenovo thinkpad
|
|
| CPEs | cpe:2.3:h:lenovo:thinkpad:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo thinkpad
|
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-10-08T13:16:40.566Z
Reserved: 2023-07-31T16:48:52.842Z
Link: CVE-2023-4029
Updated: 2024-08-02T07:17:11.608Z
Status : Modified
Published: 2023-08-17T17:15:10.313
Modified: 2024-11-21T08:34:15.683
Link: CVE-2023-4029
No data.
OpenCVE Enrichment
No data.
EUVD