Impact
A BIOS vulnerability due to improper initialization has been identified in certain Lenovo ThinkPad models. The flaw can be exploited by a local user with privileged access to modify BIOS data and execute arbitrary code, potentially compromising the confidentiality, integrity, and availability of the affected system. The weakness is classified as CWE-665.
Affected Systems
Affected firmware is present in Lenovo ThinkPad BIOS versions for the P14s Gen 5, P15v Gen 3, P16v Gen 1, T14 Gen 5, Z13 Gen 1, Z13 Gen 2, Z16 Gen 1, and Z16 Gen 2. All models running firmware prior to the update referenced in Lenovo’s advisory are vulnerable; specific vulnerable version numbers are listed in the Lenovo support page linked above.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4, indicating high severity. An EPSS score of less than 1% suggests a low likelihood of active exploitation, and the issue is not listed in the CISA KEV catalog. Exploitation requires local privileged access; once achieved, an attacker can manipulate BIOS settings and run arbitrary code, leading to full system compromise.
OpenCVE Enrichment