CVE-2022-1108: Input Validation
A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute arbitrary code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-1108?
CVE-2022-1108 is a potential vulnerability in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 firmware, which could allow an attacker with local access and elevated privileges to execute arbitrary code.
How can an attacker exploit CVE-2022-1108?
An attacker with local access and elevated privileges could exploit CVE-2022-1108 by taking advantage of the improper buffer validation in the SMI handler LenovoFlashDeviceInterface to execute arbitrary code.
What is the severity of CVE-2022-1108?
CVE-2022-1108 has a severity rating of 6.7 (high).
Which software is affected by CVE-2022-1108?
The Thinkpad X1 Fold Gen 1 firmware with version up to and excluding n2pet50w is affected by CVE-2022-1108.
How can I fix CVE-2022-1108?
Apply the latest firmware update provided by Lenovo to fix CVE-2022-1108.