First published: Thu Jan 05 2023(Updated: )
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
Credit: psirt@lenovo.com psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Thinkpad X13s Firmware | <1.47 | |
Lenovo Thinkpad X13s | ||
All of | ||
Lenovo Thinkpad X13s Firmware | <1.47 | |
Lenovo Thinkpad X13s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this buffer over-read vulnerability is CVE-2022-4433.
The Lenovo ThinkPadX13s BIOS LenovoSetupConfigDxe driver with version up to and excluding 1.47 is affected by this vulnerability.
A local attacker with elevated privileges can exploit this vulnerability to cause information disclosure.
The severity of CVE-2022-4433 is medium with a CVSS score of 4.4.
You can fix this vulnerability by updating the ThinkPadX13s BIOS LenovoSetupConfigDxe driver to a version greater than or equal to 1.47.