A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-49396 A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-141775


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-04T17:58:47.396Z

Reserved: 2023-10-03T17:36:49.034Z

Link: CVE-2023-45075

cve-icon Vulnrichment

Updated: 2024-08-02T20:14:19.819Z

cve-icon NVD

Status : Modified

Published: 2023-11-08T23:15:10.900

Modified: 2024-11-21T08:26:20.410

Link: CVE-2023-45075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.