CVE-2022-1890: Buffer Overflow
Published Jan 23, 2023
·Updated
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Affected Software
12 affected components
Lenovo Thinkbook 14-iml Firmware<cjcn38ww
Lenovo Thinkbook 14-iml
Lenovo Thinkbook 14-iil Firmware<djcn28ww
Lenovo Thinkbook 14-iil
Lenovo Thinkbook 15-iil Firmware<djcn28ww
Lenovo Thinkbook 15-iil
Lenovo Thinkbook 15-iml Firmware<cjcn38ww
Lenovo Thinkbook 15-iml
Lenovo Yoga C640-13iml Lte Firmware<chcn28ww
Lenovo Yoga C640-13iml Lte
Lenovo Yoga C640-13iml Firmware<chcn28ww
Lenovo Yoga C640-13iml
Remediation
Information
Update system firmware to the version (or newer) indicated for your model in the product Impact section of LEN-91369
Event History
Jan 23, 2023
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Lenovo Notebook product buffer overflow vulnerability?
The vulnerability ID is CVE-2022-1890.
2
What is the severity level of CVE-2022-1890?
The severity level of CVE-2022-1890 is high (CVSS score: 7.8).
3
Which Lenovo Notebook products are affected by CVE-2022-1890?
The Lenovo Thinkbook 14-iml Firmware (up to cjcn38ww) and Lenovo Thinkbook 15-iml Firmware (up to cjcn38ww) are affected.
4
How can an attacker exploit CVE-2022-1890?
An attacker with local privileges can exploit CVE-2022-1890 to execute arbitrary code.
5
Is the Lenovo Thinkbook 14-iil and Lenovo Thinkbook 15-iil vulnerable to CVE-2022-1890?
No, the Lenovo Thinkbook 14-iil and Lenovo Thinkbook 15-iil are not vulnerable to CVE-2022-1890.