Impact
A local, out-of-bounds write vulnerability in Lenovo ThinkPad BIOS firmware can allow a privileged user to execute arbitrary code in System Management Mode (SMM). This flaw, identified as CWE‑787, provides the attacker with the highest level of processor privileges, effectively bypassing operating‑system isolation and enabling full control of the system.
Affected Systems
The vulnerability impacts a broad range of Lenovo ThinkPad laptops, specifically the E14 through E16 series, L13 through L16, P1, P14s, P15v, P16, P17, P73, S2, T14, T14s, T15, T16, X1 (including 2‑in‑1 Gen 9‑10, Carbon, Extreme 2nd/3rd/4th Gen, Fold, Nano, Titanium, Yoga 4th‑8th Gen), X12 Detachable Gen 1‑2, X13 series, X390, X9‑14, X9‑15, and Z16 Gen 1‑2. All listed models with BIOS firmware versions preceding the patched release referenced in the Lenovo advisory are affected.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, and the lack of an EPSS score suggests limited publicly available exploitation data. The flaw requires local privileged access, typically through physical presence or administrative credentials, to trigger the out-of-bounds write and gain SMM execution. Although there are no known public exploits and the vulnerability is not listed in CISA’s KEV catalog, the ability to execute code in SMM represents a critical risk for environments running the affected ThinkPad models with unpatched BIOS firmware.
OpenCVE Enrichment