ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

New UEFI Firmware Vulnerabilities Impact Several Lenovo Notebook Models

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-3972
+2 in the same advisory: …3970 …3971
A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may a

A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

NVD description · AI analysis pending
6.73%
  • lenovo ideapad 3-14ada05 firmware
  • lenovo ideapad 3-14ada6 firmware
  • lenovo ideapad 3-14alc6 firmware
  • +1 more
CVE-2022-1890
+1 in the same advisory: …1891
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

NVD description · AI analysis pending
7.8<1%
  • lenovo thinkbook 14-iml firmware
  • lenovo thinkbook 14-iil firmware
  • lenovo thinkbook 15-iil firmware
  • +1 more
CVE-2022-1892
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

NVD description · AI analysis pending
7.8<1%
  • lenovo 100e 2nd gen firmware
  • lenovo 100w gen 3 firmware
  • lenovo 13w yoga firmware
  • +1 more
Full article233 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 13, 2022

Consumer electronics maker Lenovo on Tuesday rolled out fixes to contain three security flaws in its UEFI firmware affecting over 70 product models.

"The vulnerabilities can be exploited to achieve arbitrary code execution in the early phases of the platform boot, possibly allowing the attackers to hijack the OS execution flow and disable some important security features," Slovak cybersecurity firm ESET said in a series of tweets.

Tracked as CVE-2022-1890, CVE-2022-1891, and CVE-2022-1892, all three bugs relate to buffer overflow vulnerabilities that have been described by Lenovo as leading to privilege escalation on affected systems. Martin Smolár from ESET has been credited with reporting the flaws.

The bugs stem from an insufficient validation of an NVRAM variable called "DataSize" in three different drivers ReadyBootDxe, SystemLoadDefaultDxe, and SystemBootManagerDxe, resulting in a buffer overflow that could be weaponized to achieve code execution.

This is the second time Lenovo has moved to address UEFI security vulnerabilities since the start of the year. In April, the company resolved three flaws (CVE-2021-3970, CVE-2021-3971, and CVE-2021-3972) — also discovered by Smolár — that could have been abused to deploy and execute firmware implants.

Users of impacted devices are highly recommended to update their firmware to the latest version to mitigate potential threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/07/new-uefi-firmware-vulnerabilities.html