CVE-2017-3741: Low severity Lenovo Power Management vulnerability
Published Jun 3, 2017
·Updated
In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation.
Affected Software
3 affected components
Lenovo Power Management=1.67.12.19
Lenovo Power Management=1.67.12.23
Lenovo ThinkPad X1 Carbon 5
Event History
Jun 3, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3741?
CVE-2017-3741 is considered a medium severity vulnerability.
2
How do I fix CVE-2017-3741?
To fix CVE-2017-3741, update the Lenovo Power Management driver to version 1.67.12.24 or later.
3
Which hardware is affected by CVE-2017-3741?
CVE-2017-3741 affects the Lenovo ThinkPad X1 Carbon 5th generation.
4
What impact does CVE-2017-3741 have on users?
CVE-2017-3741 may allow a local user to alter the trackpoint's firmware, causing functionality issues.
5
Is CVE-2017-3741 present in earlier versions of the Lenovo Power Management driver?
Yes, CVE-2017-3741 is present in Lenovo Power Management driver versions prior to 1.67.12.24.