CWE
125
Advisory Published
Updated

CVE-2023-45079

First published: Wed Nov 08 2023(Updated: )

A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

Credit: psirt@lenovo.com

Affected SoftwareAffected VersionHow to fix
Lenovo Ideacentre C5-14IMB05<o4hkt3ca
Lenovo Ideacentre C5-14MB05 Firmware
Lenovo ideacentre 3-07ada05<o4fkt39a
Lenovo ideacentre 3-07ada05 firmware
Lenovo ideacentre 3-07imb05<m2vkt21a
Lenovo ideacentre 3-07imb05 firmware
Lenovo ideacentre g5-14imb05<o4hkt3ca
Lenovo ideacentre g5-14imb05 firmware
Lenovo Ideacentre Creator 5-14iob6 Firmware<m3gkt3da
Lenovo Ideacentre Gaming 5-14iob6 Firmware
Lenovo Ideacentre Creator 5-14iob6 Firmware<m3gkt3da
Lenovo Ideacentre Creator 5-14iob6 Firmware
Lenovo IdeaCentre G5-14AMR05 Firmware<o4zkt2ba
Lenovo ideacentre G5-14AMR05 firmware
Lenovo Ideacentre Creator 5-14iob6<m3gkt3da
Lenovo Ideacentre Gaming 5-14iob6 Firmware
Lenovo Ideacentre Mini 5<o53kt10a
Lenovo Ideacentre Mini 5
Lenovo Ideacentre Mini 5-01imh05 Firmware<o4ekt1ba
Lenovo Ideacentre Mini 5-01imh05 Firmware
Lenovo Legion T7-34IMZ5<o5fkt17a
Lenovo Legion T7-34IMZ5
Lenovo ThinkCentre M625q<m1wkt52a
Lenovo ThinkCentre M625q Firmware
Lenovo ThinkCentre M630e
Lenovo ThinkCentre M630e
Lenovo ThinkCentre M70a<m2skt29a
Lenovo ThinkCentre M70a Gen 3
Lenovo ThinkCentre M920z All-in-One Firmware<m1mkt56a
Lenovo ThinkCentre M920z All-in-One Firmware
Lenovo Ideacentre M920x Firmware<m1ukt72a
Lenovo Ideacentre M920x
Lenovo Ideacentre M920t Firmware<m1ukt72a
Lenovo ThinkCentre M920t
Lenovo ThinkCentre M920s Firmware<m1ukt72a
Lenovo ThinkCentre M920s Firmware
Lenovo Ideacentre M920q Firmware<m1ukt72a
Lenovo ThinkCentre M920q
Lenovo Thinkcentre M90t Firmware<m2tkt55a
Lenovo ThinkCentre M90t Gen 3
Lenovo ThinkCentre M90s Firmware<m2tkt55a
Lenovo ThinkCentre M90s Gen 3
Lenovo Ideacentre M90q Tiny Firmware<m2wkt5aa
Lenovo ThinkCentre M90q Gen 3
Lenovo Thinkcentre M90a Gen 2 Firmware<m2rkt57a
Lenovo ThinkCentre M90a Tiny
Lenovo Ideacentre M820z All-in-one<m1nkt62a
Lenovo Thinkcentre M820z All-in-One
Lenovo ThinkCentre M80t Firmware<m2tkt55a
Lenovo ThinkCentre M80t Gen 3
Lenovo Ideacentre M80s Firmware<m2tkt55a
Lenovo ThinkCentre M80s Gen 3
Lenovo Ideacentre M80q<m2wkt5aa
Lenovo Ideacentre M80q
Lenovo Ideacentre M75t Gen 2
Lenovo Thinkcentre M75t Gen 2 Firmware
Lenovo Ideacentre M75s Gen 2 Firmware
Lenovo Ideacentre M75s Gen 2 Firmware
Lenovo Ideacentre M75q Gen 2<m47kt30a
Lenovo Ideacentre M75q Gen 2
Lenovo Thinkcentre M75n<m33kt27a
Lenovo Thinkcentre M75n
Lenovo Ideacentre M720t Firmware<m1ukt72a
Lenovo ThinkCentre M720t
Lenovo ThinkCentre M720s Firmware<m1ukt72a
Lenovo ThinkCentre M720s
Lenovo ThinkCentre M720q Firmware<m1ukt72a
Lenovo ThinkCentre M720q
Lenovo ThinkCentre M70t<m2tkt55a
Lenovo ThinkCentre M70t
Lenovo ThinkCentre M70s Firmware<m2tkt55a
Lenovo ThinkCentre M70s
Lenovo Thinkcentre M70q Firmware<m2wkt5aa
Lenovo Thinkcentre M70q Firmware
Lenovo Thinkcentre M70c Firmware<m2vkt21a
Lenovo ThinkCentre M70c
Lenovo V50t-13iob G2<m3gkt3da
Lenovo V50t-13iob
Lenovo V55t Gen 2 13ACN<o5jkt23a
Lenovo V55t Gen 2 13ACN
Lenovo v50t-13imh firmware<m4pkt13a
Lenovo v50t-13imh firmware
Lenovo V50t-13imb G2 Firmware<o4hkt3ca
Lenovo V50t-13imb G2 Firmware
Lenovo V50s-07imb<m2vkt21a
Lenovo V50s-07imb
Lenovo v50a-24imb<m36kt32a
Lenovo V50a-24imb
Lenovo V50a-22IMB Firmware<m36kt32a
Lenovo V50a-22IMB Firmware
Lenovo v30a-24iml<m37kt31a
Lenovo V30a-24IML
Lenovo V30a-22iml Firmware<m37kt31a
Lenovo V30a-22iml Firmware
Lenovo ThinkEdge SE30 Firmware<m3fkt2da
Lenovo ThinkEdge SE30 Firmware
Lenovo ThinkStation P920 Workstation
Lenovo ThinkStation P920 Workstation
Lenovo ThinkStation P720 Workstation Firmware
Lenovo ThinkStation P720 Workstation Firmware
Lenovo Thinkstation P520c Workstation Firmware
Lenovo Thinkstation P520c Workstation Firmware
Lenovo Thinkstation P520 Workstation Firmware
Lenovo ThinkStation P520
Lenovo ThinkStation P360 Ultra Workstation Firmware
Lenovo Thinkstation P360
Lenovo ThinkStation P360 Ultra Workstation Firmware<s0ekt45a
Lenovo Thinkstation P350 Workstation Firmware
Lenovo Thinkstation P350 Workstation
Lenovo ThinkStation P348 Workstation Firmware<m3kkt3ba
Lenovo Thinkstation P348
Lenovo Thinkstation P340 Workstation Firmware<s08kt55a
Lenovo Thinkstation P340 Workstation Firmware
Lenovo Thinkstation P340 Tiny Firmware<m2wkt5aa
Lenovo Thinkstation P340 Tiny Workstation
Lenovo ThinkStation P330 Gen 2 Firmware<m1vkt72a
Lenovo Thinkstation P330 Workstation
Lenovo ThinkStation P330 Tiny Workstation Firmware<m1vkt72a
Lenovo ThinkStation P330 Tiny
Lenovo ThinkStation P330 Tiny Firmware<m1ukt72a
Lenovo ThinkStation P330 Tiny Workstation Firmware
Lenovo Thinkstation P320 Workstation Firmware<s06kt64a
Lenovo Thinkstation P320 Tiny Workstation

Remedy

Update system firmware to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-141775

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2023-45079?

    CVE-2023-45079 is a memory leakage vulnerability in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

  • Is Lenovo Ideacentre C5-14imb05 affected by CVE-2023-45079?

    Yes, Lenovo Ideacentre C5-14imb05 with firmware version up to o4hkt3ca is affected by CVE-2023-45079.

  • How severe is CVE-2023-45079?

    CVE-2023-45079 has a severity keyword of medium and a severity value of 6.7.

  • How can I fix CVE-2023-45079?

    To mitigate CVE-2023-45079, it is recommended to apply the security patches provided by Lenovo. Refer to the vendor's security advisory for specific instructions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203