First published: Thu Jan 05 2023(Updated: )
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
Credit: psirt@lenovo.com psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Lenovo Thinkpad X13s Firmware | <1.47 | |
Lenovo Thinkpad X13s Firmware | ||
Lenovo Thinkpad X13s Firmware | <1.47 | |
Lenovo Thinkpad X13s Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4435 is a buffer over-read vulnerability reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
The Lenovo Thinkpad X13s Firmware versions up to 1.47 are affected by CVE-2022-4435.
CVE-2022-4435 has a severity score of 4.4, which is considered medium.
A local attacker with elevated privileges can exploit CVE-2022-4435 to cause information disclosure.
To fix CVE-2022-4435, it is recommended to update the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver to a version that includes a security patch.