First published: Sun Jun 04 2017(Updated: )
In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Power Management Driver | =1.67.12.19 | |
Lenovo Power Management Driver | =1.67.12.23 | |
Lenovo ThinkPad X1 Carbon 5th Gen |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3741 is considered a medium severity vulnerability.
To fix CVE-2017-3741, update the Lenovo Power Management driver to version 1.67.12.24 or later.
CVE-2017-3741 affects the Lenovo ThinkPad X1 Carbon 5th generation.
CVE-2017-3741 may allow a local user to alter the trackpoint's firmware, causing functionality issues.
Yes, CVE-2017-3741 is present in Lenovo Power Management driver versions prior to 1.67.12.24.