ZeroHour

CVE-2023-4029

CVSS 3.1
6.7 medium
EPSS
<1%p9
Published
()
Modified
Description

A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

Vendors
lenovo
Products
k14 type 21cu firmware, k14 type 21cv firmware, thinkpad s2 yoga gen 8 firmware, thinkpad e14 gen 3 firmware, thinkpad e15 gen 3 firmware, thinkpad l13 gen 2 firmware, thinkpad l13 gen 3 firmware, thinkpad l13 gen 4 firmware, thinkpad l13 yoga gen 4 firmware, thinkpad l13 yoga gen 2 firmware, thinkpad l13 yoga gen 3 firmware, thinkpad l14 gen 2 firmware
Weakness
CWE-120
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.