CVE-2022-4575: Medium severity lenovo thinkpad t25 firmware vulnerability
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-4575?
CVE-2022-4575 is a vulnerability due to improper write protection of UEFI variables in the BIOS of certain ThinkPad models.
How does CVE-2022-4575 affect Lenovo ThinkPad models?
CVE-2022-4575 allows an attacker with physical or local access and elevated privileges to bypass Secure Boot on affected ThinkPad models.
What is the severity of CVE-2022-4575?
The severity of CVE-2022-4575 is medium, with a CVSS score of 6.7.
Which Lenovo ThinkPad models are affected by CVE-2022-4575?
CVE-2022-4575 affects certain ThinkPad models, including ThinkPad 25, ThinkPad L560, ThinkPad P50, ThinkPad P50s, ThinkPad P70, ThinkPad T470, ThinkPad T470s, ThinkPad T560, ThinkPad X1 Carbon 4th Gen, ThinkPad X1 Yoga 1st Gen, ThinkPad X260, ThinkPad X270, and ThinkPad Yoga 260.
How can I fix CVE-2022-4575?
To fix CVE-2022-4575, Lenovo has provided a firmware update for the affected ThinkPad models. Please refer to the Lenovo website for more information and instructions.