First published: Thu Aug 17 2023(Updated: )
A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo K14 Type 21CU Firmware | <1.12 | |
Lenovo k14 type 21cu firmware | ||
Lenovo K14 Type 21CV | <1.12 | |
Lenovo K14 Type 21CV Firmware | ||
Lenovo ThinkPad S2 Yoga Gen 8 Firmware | <1.10 | |
Lenovo ThinkPad S2 Gen 8 | ||
Lenovo ThinkPad E14 Gen 3 | <1.15 | |
Lenovo ThinkPad E14 Gen 3 Firmware | ||
Lenovo ThinkPad E15 Gen 3 | <1.15 | |
Lenovo ThinkPad E15 Gen 3 Firmware | ||
Lenovo ThinkPad L13 Gen 2 | <1.30 | |
Lenovo ThinkPad L13 Gen 2 Firmware | ||
Lenovo ThinkPad L13 Yoga Gen 3 Firmware | <1.19 | |
Lenovo ThinkPad L13 Yoga Gen 3 | ||
Lenovo ThinkPad L13 Gen 4 Firmware | <1.10 | |
Lenovo ThinkPad L13 Gen 4 Firmware | ||
Lenovo ThinkPad L13 Yoga Gen 4 | <1.10 | |
Lenovo ThinkPad L13 Yoga Gen 4 Firmware | ||
Lenovo ThinkPad L13 Yoga Gen 2 | <1.30 | |
Lenovo 13w Yoga Gen 2 Firmware | ||
Lenovo ThinkPad L13 Yoga Gen 3 | <1.19 | |
Lenovo ThinkPad L13 Yoga Gen 3 Firmware | ||
Lenovo ThinkPad L14 Gen 2 | <1.28 | |
Lenovo ThinkPad L14 | ||
Lenovo ThinkPad L14 Gen 3 Firmware | <1.23 | |
Lenovo ThinkPad L14 Gen 3 Firmware | ||
Lenovo ThinkPad L14 Gen 4 firmware | <1.06 | |
lenovo ThinkPad L14 Gen 4 firmware | ||
Lenovo ThinkPad L15 Gen 2 Firmware | <1.28 | |
Lenovo ThinkPad L15 Gen 2 | ||
Lenovo ThinkPad L15 Gen 3 Firmware | <1.23 | |
Lenovo ThinkPad L15 Gen 3 Firmware | ||
Lenovo ThinkPad L15 Gen 4 | <1.06 | |
Lenovo ThinkPad L15 Gen 4 Firmware | ||
Lenovo ThinkPad P14s Gen 2 | <1.34 | |
Lenovo ThinkPad P14s Gen 2 | ||
Lenovo Thinkpad T14 Gen 2 | <1.34 | |
Lenovo Thinkpad T14 Gen 2 | ||
Lenovo Thinkpad T14s Gen 2 Firmware | <1.37 | |
Lenovo ThinkPad T14s Gen 2i | ||
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | <1.30 | |
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | ||
Lenovo ThinkPad S2 Yoga Gen 7 Firmware | <1.19 | |
Lenovo ThinkPad S2 Gen 7 Firmware | ||
Lenovo ThinkPad S2 Yoga Gen 8 Firmware | <1.10 | |
lenovo ThinkPad s2 gen 8 firmware | ||
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | <1.30 | |
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | ||
Lenovo ThinkPad S2 Yoga Gen 7 | <1.19 | |
Lenovo ThinkPad S2 Yoga Gen 7 | ||
Lenovo ThinkPad X13 Gen 2 Firmware | <1.37 | |
Lenovo ThinkPad X13 Gen 2i | ||
All of | ||
Lenovo K14 Type 21CU Firmware | <1.12 | |
Lenovo k14 type 21cu firmware | ||
All of | ||
Lenovo K14 Type 21CV | <1.12 | |
Lenovo K14 Type 21CV Firmware | ||
All of | ||
Lenovo ThinkPad S2 Yoga Gen 8 Firmware | <1.10 | |
Lenovo ThinkPad S2 Gen 8 | ||
All of | ||
Lenovo ThinkPad E14 Gen 3 | <1.15 | |
Lenovo ThinkPad E14 Gen 3 Firmware | ||
All of | ||
Lenovo ThinkPad E15 Gen 3 | <1.15 | |
Lenovo ThinkPad E15 Gen 3 Firmware | ||
All of | ||
Lenovo ThinkPad L13 Gen 2 | <1.30 | |
Lenovo ThinkPad L13 Gen 2 Firmware | ||
All of | ||
Lenovo ThinkPad L13 Yoga Gen 3 Firmware | <1.19 | |
Lenovo ThinkPad L13 Yoga Gen 3 | ||
All of | ||
Lenovo ThinkPad L13 Gen 4 Firmware | <1.10 | |
Lenovo ThinkPad L13 Gen 4 Firmware | ||
All of | ||
Lenovo ThinkPad L13 Yoga Gen 4 | <1.10 | |
Lenovo ThinkPad L13 Yoga Gen 4 Firmware | ||
All of | ||
Lenovo ThinkPad L13 Yoga Gen 2 | <1.30 | |
Lenovo 13w Yoga Gen 2 Firmware | ||
All of | ||
Lenovo ThinkPad L13 Yoga Gen 3 | <1.19 | |
Lenovo ThinkPad L13 Yoga Gen 3 Firmware | ||
All of | ||
Lenovo ThinkPad L14 Gen 2 | <1.28 | |
Lenovo ThinkPad L14 | ||
All of | ||
Lenovo ThinkPad L14 Gen 3 Firmware | <1.23 | |
Lenovo ThinkPad L14 Gen 3 Firmware | ||
All of | ||
Lenovo ThinkPad L14 Gen 4 firmware | <1.06 | |
lenovo ThinkPad L14 Gen 4 firmware | ||
All of | ||
Lenovo ThinkPad L15 Gen 2 Firmware | <1.28 | |
Lenovo ThinkPad L15 Gen 2 | ||
All of | ||
Lenovo ThinkPad L15 Gen 3 Firmware | <1.23 | |
Lenovo ThinkPad L15 Gen 3 Firmware | ||
All of | ||
Lenovo ThinkPad L15 Gen 4 | <1.06 | |
Lenovo ThinkPad L15 Gen 4 Firmware | ||
All of | ||
Lenovo ThinkPad P14s Gen 2 | <1.34 | |
Lenovo ThinkPad P14s Gen 2 | ||
All of | ||
Lenovo Thinkpad T14 Gen 2 | <1.34 | |
Lenovo Thinkpad T14 Gen 2 | ||
All of | ||
Lenovo Thinkpad T14s Gen 2 Firmware | <1.37 | |
Lenovo ThinkPad T14s Gen 2i | ||
All of | ||
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | <1.30 | |
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | ||
All of | ||
Lenovo ThinkPad S2 Yoga Gen 7 Firmware | <1.19 | |
Lenovo ThinkPad S2 Gen 7 Firmware | ||
All of | ||
Lenovo ThinkPad S2 Yoga Gen 8 Firmware | <1.10 | |
lenovo ThinkPad s2 gen 8 firmware | ||
All of | ||
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | <1.30 | |
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | ||
All of | ||
Lenovo ThinkPad S2 Yoga Gen 7 | <1.19 | |
Lenovo ThinkPad S2 Yoga Gen 7 | ||
All of | ||
Lenovo ThinkPad X13 Gen 2 Firmware | <1.37 | |
Lenovo ThinkPad X13 Gen 2i |
Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-134879.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4029 is a buffer overflow vulnerability in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products.
The severity of CVE-2023-4029 is medium with a severity value of 6.7.
An attacker with local access and elevated privileges can exploit CVE-2023-4029 to execute arbitrary code.
Lenovo ThinkPad products with the BoardUpdateAcpiDxe driver are affected by CVE-2023-4029.
To fix CVE-2023-4029, it is recommended to apply the latest firmware update provided by Lenovo.