ZeroHour

CVE-2021-3599

CVSS 3.1
6.7 medium
EPSS
<1%p21
Published
()
Modified
Description

A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Vendors
lenovo
Products
thinkpad x380 yoga firmware, thinkpad x1 fold gen 1 firmware, thinkpad yoga 260 firmware, thinkpad yoga 11e 3rd gen firmware, thinkpad yoga 15 firmware, thinkpad yoga 370 firmware, thinkpad x12 detachable gen 1 firmware, thinkpad x390 firmware, thinkpad yoga 11e 4th gen firmware, thinkpad yoga 11e 5th gen firmware, thinkpad x250 firmware, thinkpad x260 firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.