First published: Mon Jan 23 2023(Updated: )
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Thinkbook 14-iml Firmware | <cjcn38ww | |
Lenovo Thinkbook 14-iml | ||
Lenovo Thinkbook 14-iil Firmware | <djcn28ww | |
Lenovo Thinkbook 14-iil | ||
Lenovo Thinkbook 15-iil Firmware | <djcn28ww | |
Lenovo Thinkbook 15-iil | ||
Lenovo Thinkbook 15-iml Firmware | <cjcn38ww | |
Lenovo Thinkbook 15-iml | ||
Lenovo Yoga C640-13iml Lte Firmware | <chcn28ww | |
Lenovo Yoga C640-13iml Lte | ||
Lenovo Yoga C640-13iml Firmware | <chcn28ww | |
Lenovo Yoga C640-13iml |
Update system firmware to the version (or newer) indicated for your model in the product Impact section of LEN-91369
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1891 is a vulnerability that involves a buffer overflow in the SystemLoadDefaultDxe driver in certain Lenovo Notebook products, allowing an attacker with local privileges to execute arbitrary code.
CVE-2022-1891 affects Lenovo Thinkbook 14-iml Firmware (version up to exclusive cjcn38ww), Lenovo Thinkbook 14-iil Firmware (version up to exclusive djcn28ww), Lenovo Thinkbook 15-iil Firmware (version up to exclusive djcn28ww), Lenovo Thinkbook 15-iml Firmware (version up to exclusive cjcn38ww), Lenovo Yoga C640-13iml Lte Firmware (version up to exclusive chcn28ww), and Lenovo Yoga C640-13iml Firmware (version up to exclusive chcn28ww).
CVE-2022-1891 has a severity rating of 7.8 (High).
An attacker with local privileges can exploit CVE-2022-1891 by leveraging the buffer overflow in the SystemLoadDefaultDxe driver to execute arbitrary code.
You can find more information about CVE-2022-1891 on the Lenovo product security page: https://support.lenovo.com/us/en/product_security/LEN-91369