Vulnerability in ThinkPad Models Due to Boot Services in SMI Handler
CVE-2022-1107

6.7MEDIUM

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
22 April 2022

Summary

A potential vulnerability has been identified in certain models of Lenovo ThinkPad laptops, linked to the use of Boot Services within the SmmOEMInt15 System Management Interrupt (SMI) handler. An attacker with elevated privileges could exploit this vulnerability to execute arbitrary code, posing a significant risk to system integrity and security.

Affected Version(s)

ThinkPad BIOS various

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.