ZeroHour

CVE-2022-1107

CVSS 3.1
6.7 medium
EPSS
<1%p18
Published
()
Modified
Description

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

Vendors
lenovo
Products
thinkpad 11e firmware, thinkpad helix firmware, thinkpad l560 firmware, thinkpad l570 firmware, thinkpad p50s firmware, thinkpad p51s firmware, thinkpad p52s firmware, thinkpad s540 firmware, thinkpad t550 firmware, thinkpad t560 firmware, thinkpad t570 firmware, thinkpad t580 firmware
Weakness
CWE-20, CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.