Improper Write Protection in ThinkPad BIOS Affects Lenovo Devices
CVE-2022-4575 
6.7MEDIUM
What is CVE-2022-4575?
Improper write protection of UEFI variables in the BIOS of select Lenovo ThinkPad models may allow attackers with physical or local access to exploit the system. This vulnerability can enable the bypassing of Secure Boot, potentially leading to unauthorized modifications or the execution of malicious code on affected devices. Users are advised to ensure that their systems are routinely updated and to follow recommended security practices to mitigate this risk.
Affected Version(s)
ThinkPad BIOS various
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
 High
Availability:
 High
Attack Vector:
Local
Attack Complexity:
 Low
Privileges Required:
 High
User Interaction:
 None
Scope:
 Unchanged
Timeline
- Vulnerability published 
- Vulnerability Reserved 
Credit
Lenovo thanks Krzysztof Okupski from IOActive for reporting this issue.