First published: Tue Nov 29 2016(Updated: )
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo BIOS EFI Driver | ||
Lenovo Notebook 110 14IBR BIOS | ||
Lenovo Notebook 110 15ibr | ||
Lenovo Notebook B70 80 BIOS | ||
Lenovo Notebook E31 80 BIOS | ||
Lenovo Notebook E40-80 | ||
Lenovo Notebook E41-80 | ||
Lenovo Notebook E51 80 | ||
Lenovo Notebook G40-80 BIOS | ||
Lenovo Notebook G50-80 Touch BIOS | ||
Lenovo Notebook G50-80 Touch BIOS | ||
Lenovo Notebook ideapad 300 14ibr | ||
Lenovo Ideapad 300 | ||
Lenovo Notebook ideapad 300 15ibr | ||
Lenovo Notebook ideapad 300 15isk | ||
Lenovo Ideapad 300 | ||
Lenovo Notebook ideapad 510s 12isk | ||
Lenovo K21-80 | ||
Lenovo Notebook K41 80 BIOS | ||
Lenovo Miix 710 12IKB BIOS | ||
Lenovo Notebook Xiaoxin Air 12 | ||
Lenovo Notebook Yoga 510 | ||
Lenovo Notebook Yoga 510 15ISK | ||
Lenovo Yoga 710-11IKB | ||
Lenovo Yoga 710-11IKB | ||
Lenovo Notebook Yoga 900 13ISK | ||
Lenovo Notebook Yoga 900s 12isk | ||
Lenovo ThinkServer TS150 BIOS | ||
Lenovo ThinkServer TS450 BIOS | ||
Lenovo Notebook 110 14ibr bios | ||
Lenovo Notebook 110 15ibr | ||
Lenovo Notebook B70 80 BIOS | ||
Lenovo Notebook E31 80 BIOS | ||
Lenovo Notebook E40-80 | ||
Lenovo Notebook E41-80 | ||
Lenovo Notebook E51 80 | ||
Lenovo G40-80 | ||
Lenovo Notebook G50-80 | ||
Lenovo G50-80 Touch Firmware | ||
Lenovo Notebook ideapad 300 14ibr bios | ||
Lenovo Notebook ideapad 300 14isk bios | ||
Lenovo Notebook ideapad 300 15ibr BIOS | ||
Lenovo Notebook ideapad 300 | ||
Lenovo Ideapad 300 | ||
Lenovo Notebook ideapad 510s 12isk bios | ||
Lenovo K21-80 | ||
Lenovo K41-80 | ||
Lenovo Miix 710 12IKB BIOS | ||
Lenovo Notebook Xiaoxin Air 12 | ||
Lenovo Notebook Yoga 510 14ISK BIOS | ||
Lenovo Notebook Yoga 510 | ||
Lenovo Notebook Yoga 710 11IKB BIOS | ||
Lenovo Notebook Yoga 710 11ISK BIOS | ||
Lenovo Yoga 900 | ||
Lenovo Notebook Yoga 900S 12ISK BIOS | ||
Lenovo ThinkServer TS150 BIOS | ||
Lenovo ThinkServer TS450 BIOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8224 has been assigned a high severity rating due to the potential for privilege escalation and denial of service attacks.
To fix CVE-2016-8224, Lenovo recommends updating the affected BIOS versions to the latest available firmware release.
CVE-2016-8224 affects various Lenovo Notebook and ThinkServer systems with specific BIOS versions.
An attacker with administrative privileges can exploit CVE-2016-8224 to bypass Intel Management Engine protections, leading to potential system compromise.
As of now, there is no publicly available exploit code for CVE-2016-8224, but the vulnerability can allow for significant system manipulation if exploited.