CVE-2022-1107: Input Validation
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1107?
CVE-2022-1107 has a high severity rating as it may allow an attacker with elevated privileges to execute code.
How do I fix CVE-2022-1107?
To fix CVE-2022-1107, update the firmware of affected Lenovo ThinkPad models to the latest version available.
Which Lenovo ThinkPad models are affected by CVE-2022-1107?
CVE-2022-1107 affects multiple Lenovo ThinkPad models including the 11e, Helix, P50s, P51s, and several others.
Can CVE-2022-1107 be exploited remotely?
No, CVE-2022-1107 requires an attacker to have elevated privileges on the device for exploitation.
What type of vulnerability is CVE-2022-1107?
CVE-2022-1107 is a firmware vulnerability related to the use of Boot Services in the SmmOEMInt15 SMI handler.