First published: Mon Nov 13 2017(Updated: )
A local privilege escalation vulnerability was identified in the Realtek audio driver versions prior to 6.0.1.8224 in some Lenovo ThinkPad products. An attacker with local privileges could execute code with administrative privileges.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Realtek HD Audio Codec Drivers | <6.0.1.8224 | |
Lenovo ThinkPad 10 firmware | ||
Lenovo ThinkPad 11e firmware | ||
Lenovo ThinkPad 13 firmware | ||
Lenovo ThinkPad L450 | ||
Lenovo ThinkPad L460 Firmware | ||
Lenovo ThinkPad L470 | ||
Lenovo ThinkPad L470 | ||
Lenovo ThinkPad L560 Firmware | ||
Lenovo ThinkPad P50 Firmware | ||
Lenovo ThinkPad P50s BIOS | ||
Lenovo ThinkPad P51s Firmware | ||
Lenovo ThinkPad P70 BIOS | ||
Lenovo ThinkPad P71 | ||
Lenovo ThinkPad S1 Firmware | ||
Lenovo ThinkPad S1 Yoga | ||
Lenovo ThinkPad S1 Yoga 12 BIOS | ||
Lenovo ThinkPad S2 | ||
Lenovo ThinkPad T440 | ||
Lenovo ThinkPad T440p Firmware | ||
Lenovo ThinkPad T440s | ||
Lenovo ThinkPad T450 Firmware | ||
Lenovo ThinkPad T450s Firmware | ||
Lenovo ThinkPad T460 firmware | ||
Lenovo ThinkPad T460p BIOS | ||
Lenovo ThinkPad T460s | ||
Lenovo ThinkPad T470 | ||
Lenovo ThinkPad T470p | ||
Lenovo ThinkPad T470s | ||
Lenovo ThinkPad T540p Firmware | ||
Lenovo ThinkPad T550 | ||
Lenovo ThinkPad T560 Firmware | ||
Lenovo ThinkPad T570 | ||
Lenovo ThinkPad W540 | ||
Lenovo ThinkPad W541 Firmware | ||
Lenovo ThinkPad W550s | ||
Lenovo ThinkPad X1 Carbon | ||
Lenovo ThinkPad X1 Tablet Firmware | ||
Lenovo ThinkPad X1 Yoga | ||
Lenovo ThinkPad X1 Carbon | ||
Lenovo ThinkPad x240 firmware | ||
Lenovo ThinkPad x240s BIOS | ||
Lenovo ThinkPad x250 firmware | ||
Lenovo ThinkPad x260 | ||
Lenovo ThinkPad X270 | ||
Lenovo ThinkPad X270 | ||
Lenovo ThinkPad Yoga 11e Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3767 is a local privilege escalation vulnerability in Realtek audio driver versions prior to 6.0.1.8224 in some Lenovo ThinkPad products.
An attacker with local privileges can exploit CVE-2017-3767 to execute code with administrative privileges.
Some Lenovo ThinkPad products with Realtek audio driver versions prior to 6.0.1.8224 are affected by CVE-2017-3767.
The severity of CVE-2017-3767 is high, with a CVSS severity score of 7.8 out of 10.
You can find more information about CVE-2017-3767 on the Lenovo Product Security website.