CVE-2016-8222: Medium severity lenovo thinkpad 10 ella 2 bios vulnerability
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be altered (such as boot sequence). The setting or changing of BIOS passwords is not affected by this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8222?
CVE-2016-8222 has been classified as a medium severity vulnerability that could lead to denial of service or unauthorized access to BIOS variables.
How do I fix CVE-2016-8222?
Fixing CVE-2016-8222 involves applying the latest BIOS updates from Lenovo which address this vulnerability.
Which systems are affected by CVE-2016-8222?
CVE-2016-8222 affects various Lenovo ThinkPad models including the ThinkPad 10, Yoga 11e series, and several others listed in the vulnerability details.
Can an attacker exploit CVE-2016-8222 remotely?
No, an attacker must have Windows administrator-level privileges on the affected system to exploit CVE-2016-8222.
What impact does CVE-2016-8222 have on system security?
CVE-2016-8222 could allow an attacker to gain access to sensitive BIOS settings or cause a denial of service attack, impacting system integrity.