ZeroHour

CVE-2022-1892

CVSS 3.1
7.8 high
EPSS
<1%p27
Published
()
Modified
Description

A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

Vendors
lenovo
Products
100e 2nd gen firmware, 100w gen 3 firmware, 13w yoga firmware, 14w gen 2 firmware, 300e 2nd gen firmware, 300w gen 3 firmware, 500w gen 3 firmware, 730s-13iml firmware, flex 3-11ada05 firmware, flex 5-14alc05 firmware, flex 5-14are05 firmware, flex 5-14iil05 firmware
Weakness
CWE-122, CWE-120
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news