ZeroHour

CVE-2023-4028

CVSS 3.1
6.7 medium
EPSS
<1%p9
Published
()
Modified
Description

A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

Vendors
lenovo
Products
13w yoga firmware, 13w yoga gen 2 firmware, ideapad 1-11ada05 firmware, ideapad 1-11igl05 firmware, ideapad 1-14ada05 firmware, ideapad 1-14igl05 firmware, flex 5-14alc05 firmware, flex 5-14are05 firmware, flex 5-14iil05 firmware, flex 5-14itl05 firmware, flex 5-15alc05 firmware, flex 5-15iil05 firmware
Weakness
CWE-120
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.