Impact
A missing authentication flaw in Lenovo BIOS firmware permits a local user with elevated privileges to invoke arbitrary WMI commands that can trigger a System Management Interrupt handler. This grants the attacker the ability to execute code at the highest level within the firmware, potentially compromising BIOS integrity and enabling broader system compromise.
Affected Systems
The vulnerability affects BIOS firmware on a wide array of Lenovo laptops, including IdeaPad, Legion, ThinkBook, Yoga, and other series such as Lenovo S14 G3, V14 G6, and V15 series. Specific models impacted include the IdeaPad 5 15ABA7, IdeaPad Pro 5 16AGP11, 16ASP10, 16IAH10, 16IMH9, 16IPH11, 16IRH8, IdeaPad Slim 3 14ITN9, 15AMN8, 16ARP10, 16IRH10R, 16IRH8, 16IRU9, LOQ 15ARP10E, LOQ 15IAX9E, Legion 5 15AHP10, 15AKP10, 15APH9, 15IAX10, 15IRX10, 15IRX9, Legion 7 16AGP11, 16IAX10, Legion 9 16IRX9, Legion Pro 5 16ADR10, 16AFR10, 16ARX8, 16IAX10, 16IRX10, 16IRX9, Legion Pro 7 16ADR10H, 16AFR10H, 16ARX8H, 16IAX10H, 16IRX9H, Legion Slim 5 14APH8, Lenovo S14 G3 IAP, Lenovo V14 G6 ITN, Lenovo V15 G2 IJL, V15 G4 AMN, V15 G4 IAH, V15 G5 IRL, V15 G6 ARP, ThinkBook 16p G5 IRX, 16p G6 ADR, 16p G6 IAX, ThinkBook Plus G4 IRU, ThinkBook Plus G5 tab & ThinkBook Plus G5 Station, ThinkBook Plus G6 Rollable, Yoga 9 14IRP8, 2‑in‑1 14ILL10, 2‑in‑1 14IMH9, Yoga Book 9 13IMU9, 14IAH10, Yoga Pro 7 15IPH11, Yoga Pro 9 14IRP8, and Yoga Pro 9 16IMH9. Affected version information is not supplied in the advisory; users should refer to the Lenovo support page for applicable firmware releases.
Risk and Exploitability
The CVSS base score of 6.7 reflects moderate severity, primarily due to the local nature of the exploit and the requirement for pre‑existing local privilege. The EPSS score of less than 1% indicates that the vulnerability is currently considered unlikely to be widely exploited, and the absence from the CISA KEV catalog further suggests no known active exploitation. Nevertheless, because a successful exploit allows access to the highest firmware level, it poses significant risk in environments where insider threats or physical compromise are possible. No public or confirmed exploits have been reported, so the primary defense remains applying the Lenovo firmware updates provided in advisory LEN‑220440.
OpenCVE Enrichment