ZeroHour

CVE-2022-48188

CVSS 3.1
7.8 high
EPSS
<1%p9
Published
()
Modified
Description

A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.

Vendors
lenovo
Products
ideacentre aio 3 21itl7 firmware, ideacentre aio 3-22itl6 firmware, ideacentre aio 3-24itl6 firmware, ideacentre aio 3-27itl6 firmware, thinkcentre m720e firmware, thinkcentre m720q firmware, thinkcentre m720s firmware, thinkcentre m720t firmware, thinkcentre m725s firmware, thinkcentre m75s gen 2 firmware, thinkcentre m75t gen 2 firmware, thinkcentre m920q firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.