First published: Mon Jan 23 2023(Updated: )
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Thinkbook 14-iml Firmware | <cjcn38ww | |
Lenovo Thinkbook 14-iml | ||
Lenovo Thinkbook 14-iil Firmware | <djcn28ww | |
Lenovo Thinkbook 14-iil | ||
Lenovo Thinkbook 15-iil Firmware | <djcn28ww | |
Lenovo Thinkbook 15-iil | ||
Lenovo Thinkbook 15-iml Firmware | <cjcn38ww | |
Lenovo Thinkbook 15-iml | ||
Lenovo Yoga C640-13iml Lte Firmware | <chcn28ww | |
Lenovo Yoga C640-13iml Lte | ||
Lenovo Yoga C640-13iml Firmware | <chcn28ww | |
Lenovo Yoga C640-13iml |
Update system firmware to the version (or newer) indicated for your model in the product Impact section of LEN-91369
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-1890.
The severity level of CVE-2022-1890 is high (CVSS score: 7.8).
The Lenovo Thinkbook 14-iml Firmware (up to cjcn38ww) and Lenovo Thinkbook 15-iml Firmware (up to cjcn38ww) are affected.
An attacker with local privileges can exploit CVE-2022-1890 to execute arbitrary code.
No, the Lenovo Thinkbook 14-iil and Lenovo Thinkbook 15-iil are not vulnerable to CVE-2022-1890.