First published: Mon Jun 05 2023(Updated: )
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Ideacentre AIO 3 21ITL7 | <o5akt33 | |
Lenovo Ideacentre AIO 3 21ITL7 Firmware | ||
Lenovo Ideacentre AIO 3-22ITL6 Firmware | <o5akt33 | |
Lenovo Ideacentre AIO 3-22ITL6 Firmware | ||
Lenovo ideacentre aio 3-24itl6 | <o5akt33 | |
Lenovo ideacentre aio 3-24itl6 firmware | ||
Lenovo ideacentre aio 3-27itl6 firmware | <o5akt33 | |
Lenovo ideacentre aio 3-27itl6 firmware | ||
Lenovo ThinkCentre M720e | <m1zkt40a | |
Lenovo ThinkCentre M720e | ||
Lenovo ThinkCentre M720q Firmware | <m1ukt70a | |
Lenovo ThinkCentre M720q | ||
Lenovo ThinkCentre M720s Firmware | <m1ukt70a | |
Lenovo ThinkCentre M720s | ||
Lenovo Ideacentre M720t Firmware | <m1ukt70a | |
Lenovo ThinkCentre M720t | ||
Lenovo ThinkCentre M725s Firmware | <m25kt63a | |
Lenovo ThinkCentre M725s Firmware | ||
Lenovo Ideacentre M75s Gen 2 Firmware | <m46kt30a | |
Lenovo Ideacentre M75s Gen 2 Firmware | ||
Lenovo Ideacentre M75s Gen 2 Firmware | <m3bkt30a | |
Lenovo Ideacentre M75t Gen 2 | <m46kt30a | |
Lenovo Thinkcentre M75t Gen 2 Firmware | ||
Lenovo Ideacentre M75t Gen 2 | <m3akt4ca | |
Lenovo Ideacentre M920q Firmware | <m1ukt70a | |
Lenovo ThinkCentre M920q | ||
Lenovo ThinkCentre M920s Firmware | <m1ukt70a | |
Lenovo ThinkCentre M920s Firmware | ||
Lenovo Ideacentre M920t Firmware | <m1ukt70a | |
Lenovo ThinkCentre M920t | ||
Lenovo Ideacentre M920x Firmware | <m1ukt70a | |
Lenovo Ideacentre M920x | ||
Lenovo ThinkCentre M920z All-in-One Firmware | <m1mkt55a | |
Lenovo ThinkCentre M920z All-in-One | ||
Lenovo ideacentre 510s-07icb | <m22kt48a | |
Lenovo ideacentre 510s-07icb firmware | ||
Lenovo ideacentre 510s-07icb | <m22kt49a | |
Lenovo ideacentre 510s-07ick | <m30kt28a | |
Lenovo ideacentre 510s-07ick firmware | ||
Lenovo ideacentre 510s-07ick | <m1zkt40a | |
Lenovo ideacentre 720-18apr | <m25kt63a | |
Lenovo ideacentre 720-18apr firmware | ||
Lenovo V30a-22ITL | <o5akt33 | |
Lenovo V30a-22ITL | ||
Lenovo v30a-24itl | <o5akt33 | |
Lenovo v30a-24itl firmware | ||
Lenovo V530s-07ICB | <m22kt49a | |
Lenovo V530 | ||
Lenovo V530s-07ICB | <m1zkt40a | |
Lenovo V530s-07ICB | ||
Lenovo ThinkStation P330 Tiny Firmware | <m1ukt70a | |
Lenovo ThinkStation P330 Tiny | ||
Lenovo ThinkStation P360 Ultra Workstation Firmware | <s0fkt27a | |
Lenovo ThinkStation P360 Ultra | ||
Lenovo ThinkStation P520 | <s03kt58a | |
Lenovo ThinkStation P520 Workstation | ||
Lenovo Thinkstation P520c | <s03kt58a | |
Lenovo Thinkstation P520c Workstation Firmware |
Update system firmware to the version (or newer) indicated for your model in the related Lenovo advisory: https://support.lenovo.com/us/en/product_security/LEN-124495 https://support.lenovo.com/us/en/product_security/LEN-124495
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48188 is considered a critical vulnerability due to the potential for local privilege escalation.
CVE-2022-48188 affects specific Lenovo Desktop and ThinkStation models with vulnerable firmware versions.
An attacker with local access can exploit CVE-2022-48188 by triggering a buffer overflow to execute arbitrary code.
To mitigate CVE-2022-48188, users should update their BIOS firmware to the latest version provided by Lenovo.
Exploitation of CVE-2022-48188 could allow an attacker to gain elevated privileges, compromising the affected system.