Memory Leakage Vulnerability in NvmramSmm Driver from Lenovo
CVE-2023-45079

6.7MEDIUM

Key Information:

Vendor
Lenovo
Status
Vendor
CVE Published:
8 November 2023

Summary

A memory leakage vulnerability has been identified in Lenovo's NvmramSmm SMM driver. This issue may allow a local attacker with elevated privileges to write to non-volatile RAM (NVRAM) variables, potentially compromising the integrity and security of critical data stored in the system. Users are advised to assess the security of their devices and to apply mitigations as they become available.

Affected Version(s)

BIOS various

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Souhardya Sardar of Cyberstanc for reporting this issue.
.