Memory Leakage Vulnerability in NvmramSmm Driver from Lenovo
CVE-2023-45079
6.7MEDIUM
Summary
A memory leakage vulnerability has been identified in Lenovo's NvmramSmm SMM driver. This issue may allow a local attacker with elevated privileges to write to non-volatile RAM (NVRAM) variables, potentially compromising the integrity and security of critical data stored in the system. Users are advised to assess the security of their devices and to apply mitigations as they become available.
Affected Version(s)
BIOS various
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Souhardya Sardar of Cyberstanc for reporting this issue.