7.2
CWE
20 269
Advisory Published
Updated

CVE-2022-1107: Input Validation

First published: Fri Apr 22 2022(Updated: )

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

Credit: psirt@lenovo.com

Affected SoftwareAffected VersionHow to fix
Lenovo Thinkpad 11e Firmware<n15et78w
Lenovo Thinkpad 11e
Lenovo Thinkpad Helix Firmware<n17eta8w
Lenovo Thinkpad Helix
Lenovo Thinkpad L560 Firmware<n1het85w
Lenovo Thinkpad L560
Lenovo Thinkpad L570 Firmware<n1xet65w
Lenovo Thinkpad L570
Lenovo Thinkpad P50s Firmware<n1ket46w
Lenovo Thinkpad P50s
Lenovo Thinkpad P51s Firmware<n1vet50w
Lenovo Thinkpad P51s
Lenovo Thinkpad P52s Firmware<n27et36w
Lenovo Thinkpad P52s
Lenovo Thinkpad S540 Firmware<gpet80ww
Lenovo Thinkpad S540
Lenovo Thinkpad T550 Firmware<n11et50w
Lenovo Thinkpad T550
Lenovo Thinkpad T560 Firmware<n1ket46w
Lenovo Thinkpad T560
Lenovo Thinkpad T570 Firmware<n1vet50w
Lenovo Thinkpad T570
Lenovo Thinkpad T580 Firmware<n27et36w
Lenovo Thinkpad T580
Lenovo Thinkpad X1 Tablet Gen 1 Firmware<n1let86w
Lenovo Thinkpad X1 Tablet Gen 1
Lenovo Thinkpad X1 Tablet Gen 2 Firmware<n1oet50w
Lenovo Thinkpad X1 Tablet Gen 2
Lenovo Thinkpad W540 Firmware<gnet92ww
Lenovo Thinkpad W540
Lenovo Thinkpad W541 Firmware<gnet92ww
Lenovo Thinkpad W541
Lenovo Thinkpad W550s Firmware<n11et50w
Lenovo Thinkpad W550s
Lenovo Thinkpad X1 Carbon 3rd Gen Firmware<n14et52w
Lenovo Thinkpad X1 Carbon 3rd Gen
Lenovo Thinkpad X1 Carbon 4th Gen Firmware<n1fet70w
Lenovo Thinkpad X1 Carbon 4th Gen
Lenovo Thinkpad X1 Carbon 5th Gen Kabylake Firmware<n1met55w
Lenovo Thinkpad X1 Carbon 5th Gen Kabylake
Lenovo Thinkpad X1 Carbon 5th Gen Skylake Firmware<n1met55w
Lenovo Thinkpad X1 Carbon 5th Gen Skylake
Lenovo Thinkpad X1 Yoga Firmware<n1fet70w
Lenovo Thinkpad X1 Yoga
Lenovo Thinkpad X1 Yoga Gen 2 Firmware<n1net47w
Lenovo Thinkpad X1 Yoga Gen 2
Lenovo Thinkpad X1 Yoga Gen 3 Firmware<n25et50w
Lenovo Thinkpad X1 Yoga Gen 3
Lenovo Thinkpad X250 Firmware<n10et58w
Lenovo Thinkpad X250
Lenovo Thinkpad X280 Firmware<n20et44w
Lenovo Thinkpad X280
Lenovo Thinkpad X390 Firmware<n2let60w
Lenovo Thinkpad X390
Lenovo Thinkpad 11e Yoga Firmware<n15et78w
Lenovo Thinkpad 11e Yoga
Lenovo Thinkpad Yoga 15 Firmware<n19et61w
Lenovo Thinkpad Yoga 15
Lenovo Thinkpad Yoga 260 Firmware<n1get98w
Lenovo Thinkpad Yoga 260

Remedy

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-84943.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203