First published: Mon Jan 23 2023(Updated: )
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Thinkbook 14 IMl Firmware | <cjcn38ww | |
Lenovo Thinkbook 14 IMl | ||
Lenovo ThinkBook 14 iil Firmware | <djcn28ww | |
Lenovo ThinkBook 14 iil | ||
Lenovo Thinkbook 15-iil Firmware | <djcn28ww | |
Lenovo Thinkbook 15-iil Firmware | ||
Lenovo ThinkBook 15-IML Firmware | <cjcn38ww | |
Lenovo ThinkBook 15 IML | ||
Lenovo Yoga C640-13IML LTE Firmware | <chcn28ww | |
Lenovo Yoga C640-13IML LTE Firmware | ||
Lenovo C640-IML Firmware | <chcn28ww | |
Lenovo Yoga C640-13IML LTE Firmware |
Update system firmware to the version (or newer) indicated for your model in the product Impact section of LEN-91369
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-1890.
The severity level of CVE-2022-1890 is high (CVSS score: 7.8).
The Lenovo Thinkbook 14-iml Firmware (up to cjcn38ww) and Lenovo Thinkbook 15-iml Firmware (up to cjcn38ww) are affected.
An attacker with local privileges can exploit CVE-2022-1890 to execute arbitrary code.
No, the Lenovo Thinkbook 14-iil and Lenovo Thinkbook 15-iil are not vulnerable to CVE-2022-1890.