CVE-2023-5075: Buffer Overflow
Published Nov 8, 2023
·Updated
A buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevated privileges to execute arbitrary code.
Affected Software
2 affected components
All of the following
Lenovo Ideapad Duet 3 10igl5 Firmware<eqcn39ww
Lenovo Ideapad Duet 3 10igl5
Remediation
Information
Update system firmware to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-141775
Event History
Nov 8, 2023
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-5075.
2
What is the severity of CVE-2023-5075?
The severity of CVE-2023-5075 is medium.
3
What is the affected software?
The affected software is Lenovo Ideapad Duet 3 10igl5 Firmware.
4
How can a local attacker exploit CVE-2023-5075?
A local attacker with elevated privileges can exploit CVE-2023-5075 by executing arbitrary code.
5
Is Lenovo Ideapad Duet 3 10igl5 vulnerable to CVE-2023-5075?
Yes, Lenovo Ideapad Duet 3 10igl5 is vulnerable to CVE-2023-5075.
6
How can I fix CVE-2023-5075?
To fix CVE-2023-5075, apply the latest firmware update provided by Lenovo.
7
Where can I find more information about CVE-2023-5075?
More information about CVE-2023-5075 can be found on the Lenovo Product Security website.