First published: Thu Jan 05 2023(Updated: )
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.
Credit: psirt@lenovo.com psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Thinkpad X13s Firmware | <1.47 | |
Lenovo Thinkpad X13s | ||
All of | ||
Lenovo Thinkpad X13s Firmware | <1.47 | |
Lenovo Thinkpad X13s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4434 is a buffer over-read vulnerability in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.
CVE-2022-4434 has a severity rating of 4.4 (medium).
Lenovo Thinkpad X13s Firmware versions up to and including 1.47 are affected by CVE-2022-4434.
No, Lenovo Thinkpad X13s hardware is not vulnerable to CVE-2022-4434.
To fix CVE-2022-4434, users should update their Lenovo Thinkpad X13s Firmware to version 1.48 or later.