Description
A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modify data and execute arbitrary code.
Published: 2026-03-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation / Arbitrary Code Execution
Action: Patch ASAP
AI Analysis

Impact

A BIOS vulnerability due to improper initialization has been identified in certain Lenovo ThinkPad models. The flaw can be exploited by a local user with privileged access to modify BIOS data and execute arbitrary code, potentially compromising the confidentiality, integrity, and availability of the affected system. The weakness is classified as CWE-665.

Affected Systems

Affected firmware is present in Lenovo ThinkPad BIOS versions for the P14s Gen 5, P15v Gen 3, P16v Gen 1, T14 Gen 5, Z13 Gen 1, Z13 Gen 2, Z16 Gen 1, and Z16 Gen 2. All models running firmware prior to the update referenced in Lenovo’s advisory are vulnerable; specific vulnerable version numbers are listed in the Lenovo support page linked above.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.4, indicating high severity. An EPSS score of less than 1% suggests a low likelihood of active exploitation, and the issue is not listed in the CISA KEV catalog. Exploitation requires local privileged access; once achieved, an attacker can manipulate BIOS settings and run arbitrary code, leading to full system compromise.

Generated by OpenCVE AI on March 17, 2026 at 15:26 UTC.

Remediation

Vendor Solution

Update to the version (or newer) indicated for your model in the Product Impact section of the advisory:  https://support.lenovo.com/us/en/product_security/LEN-213040


OpenCVE Recommended Actions

  • Apply the firmware update for your ThinkPad model as specified in Lenovo’s product security advisory (https://support.lenovo.com/us/en/product_security/LEN-213040).
  • Verify your BIOS version; if it is older than the latest release, schedule an update immediately.

Generated by OpenCVE AI on March 17, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 20 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
Title Improper BIOS Initialization Allowing Local Privilege Escalation on Lenovo ThinkPads

Thu, 12 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Mar 2026 20:45:00 +0000

Type Values Removed Values Added
Description A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modify data and execute arbitrary code.
First Time appeared Lenovo
Lenovo thinkpad P14s Gen 5 Bios
Lenovo thinkpad P15v Gen 3 Bios
Lenovo thinkpad P16v Gen 1 Bios
Lenovo thinkpad T14 Gen 5 Bios
Lenovo thinkpad Z13 Gen 1 Bios
Lenovo thinkpad Z13 Gen 2 Bios
Lenovo thinkpad Z16 Gen 1 Bios
Lenovo thinkpad Z16 Gen 2 Bios
Weaknesses CWE-665
CPEs cpe:2.3:a:lenovo:thinkpad_p14s_gen_5_bios:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:thinkpad_p15v_gen_3_bios:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:thinkpad_p16v_gen_1_bios:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:thinkpad_t14_gen_5_bios:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:thinkpad_z13_gen_1_bios:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:thinkpad_z13_gen_2_bios:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:thinkpad_z16_gen_1_bios:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:thinkpad_z16_gen_2_bios:*:*:*:*:*:*:*:*
Vendors & Products Lenovo
Lenovo thinkpad P14s Gen 5 Bios
Lenovo thinkpad P15v Gen 3 Bios
Lenovo thinkpad P16v Gen 1 Bios
Lenovo thinkpad T14 Gen 5 Bios
Lenovo thinkpad Z13 Gen 1 Bios
Lenovo thinkpad Z13 Gen 2 Bios
Lenovo thinkpad Z16 Gen 1 Bios
Lenovo thinkpad Z16 Gen 2 Bios
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo Thinkpad P14s Gen 5 Bios Thinkpad P15v Gen 3 Bios Thinkpad P16v Gen 1 Bios Thinkpad T14 Gen 5 Bios Thinkpad Z13 Gen 1 Bios Thinkpad Z13 Gen 2 Bios Thinkpad Z16 Gen 1 Bios Thinkpad Z16 Gen 2 Bios
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-03-13T03:55:41.336Z

Reserved: 2026-01-14T14:41:45.333Z

Link: CVE-2026-0940

cve-icon Vulnrichment

Updated: 2026-03-12T15:37:55.579Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-11T21:16:13.887

Modified: 2026-03-12T21:08:22.643

Link: CVE-2026-0940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-20T15:37:15Z

Weaknesses