CVE-2021-3719: Input Validation
A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-3719?
CVE-2021-3719 is a potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models.
How does CVE-2021-3719 affect Lenovo ThinkCentre E93 firmware?
CVE-2021-3719 affects Lenovo ThinkCentre E93 firmware version up to but not including fbktdfa.
How does CVE-2021-3719 affect Lenovo ThinkCentre M600 firmware?
CVE-2021-3719 affects Lenovo ThinkCentre M600 firmware version up to but not including m00kt65a.
What is the severity of CVE-2021-3719?
CVE-2021-3719 has a severity rating of 6.7 (high).
How can I fix CVE-2021-3719?
To fix CVE-2021-3719, Lenovo has provided a firmware update for the affected ThinkCentre and ThinkStation models. Please refer to the Lenovo Product Security Advisories page for more information and download the appropriate update.