CVE-2022-1891: Buffer Overflow
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-1891?
CVE-2022-1891 is a vulnerability that involves a buffer overflow in the SystemLoadDefaultDxe driver in certain Lenovo Notebook products, allowing an attacker with local privileges to execute arbitrary code.
Which Lenovo Notebook products are affected by CVE-2022-1891?
CVE-2022-1891 affects Lenovo Thinkbook 14-iml Firmware (version up to exclusive cjcn38ww), Lenovo Thinkbook 14-iil Firmware (version up to exclusive djcn28ww), Lenovo Thinkbook 15-iil Firmware (version up to exclusive djcn28ww), Lenovo Thinkbook 15-iml Firmware (version up to exclusive cjcn38ww), Lenovo Yoga C640-13iml Lte Firmware (version up to exclusive chcn28ww), and Lenovo Yoga C640-13iml Firmware (version up to exclusive chcn28ww).
What is the severity of CVE-2022-1891?
CVE-2022-1891 has a severity rating of 7.8 (High).
How can an attacker exploit CVE-2022-1891?
An attacker with local privileges can exploit CVE-2022-1891 by leveraging the buffer overflow in the SystemLoadDefaultDxe driver to execute arbitrary code.
Where can I find more information about CVE-2022-1891?
You can find more information about CVE-2022-1891 on the Lenovo product security page: https://support.lenovo.com/us/en/product_security/LEN-91369