ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

New UEFI Firmware Flaws Reported in Several Lenovo Notebook Models

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-3972
+2 in the same advisory: …3970 …3971
A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may a

A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

NVD description · AI analysis pending
6.73%
  • lenovo ideapad 3-14ada05 firmware
  • lenovo ideapad 3-14ada6 firmware
  • lenovo ideapad 3-14alc6 firmware
  • +1 more
CVE-2022-1890
+1 in the same advisory: …1891
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

NVD description · AI analysis pending
7.8<1%
  • lenovo thinkbook 14-iml firmware
  • lenovo thinkbook 14-iil firmware
  • lenovo thinkbook 15-iil firmware
  • +1 more
CVE-2022-1892
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

NVD description · AI analysis pending
7.8<1%
  • lenovo 100e 2nd gen firmware
  • lenovo 100w gen 3 firmware
  • lenovo 13w yoga firmware
  • +1 more
CVE-2022-3430
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot

A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

NVD description · AI analysis pending
6.7<1%
  • lenovo d330-10igl firmware
  • lenovo ideapad 5 pro 16iah7 firmware
  • lenovo ideapad 5 pro 16arh7 firmware
  • +1 more
CVE-2022-3431
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow a

A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

NVD description · AI analysis pending
7.8<1%
  • lenovo ideapad creator 5-16ach6 firmware
  • lenovo ideapad 5 pro-16ihu6 firmware
  • lenovo ideapad 5 pro-16ach6 firmware
  • +1 more
CVE-2022-3432
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with

A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

NVD description · AI analysis pending
6.7<1%
  • lenovo ideapad y700-14isk firmware
Full article486 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 10, 2022

PC maker Lenovo has addressed yet another set of three shortcomings in the Unified Extensible Firmware Interface (UEFI) firmware affecting several Yoga, IdeaPad, and ThinkBook devices.

"The vulnerabilities allow disabling UEFI Secure Boot or restoring factory default Secure Boot databases (incl. dbx): all simply from an OS," Slovak cybersecurity firm ESET explained in a series of tweets.

UEFI refers to software that acts as an interface between the operating system and the firmware embedded in the device's hardware. Because UEFI is responsible for launching the operating system when a device is powered on, it has made the technology an attractive option for threat actors looking to drop malware that's difficult to detect and remove.

Viewed in that light, the flaws, tracked as CVE-2022-3430, CVE-2022-3431, and CVE-2022-3432, could be abused by an adversary to turn off Secure Boot, a security mechanism that's designed to prevent malicious programs from loading during the boot process.

Lenovo's advisory describes the vulnerabilities as follows -

  • CVE-2022-3430: A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify Secure Boot setting by modifying an NVRAM variable.
  • CVE-2022-3431: A potential vulnerability in a driver used during the manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify Secure Boot setting by modifying an NVRAM variable.
  • CVE-2022-3432: A potential vulnerability in a driver used during the manufacturing process on the IdeaPad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify Secure Boot setting by modifying an NVRAM variable.

In other words, disabling the UEFI Secure Boot makes it possible for threat actors to execute rogue boot loaders, granting the attackers privileged access to the compromised hosts.

ESET said the vulnerabilities weren't lapses in the source code per se, but rather came into being because the "drivers were meant to be used only during the manufacturing process but were mistakenly included in the production."

The latest update marks the third time Lenovo has moved to patch flaws in its UEFI firmware since the start of the year, all of which have been discovered and reported by ESET researcher Martin Smolár.

While the first set of issues (CVE-2021-3970, CVE-2021-3971, and CVE-2021-3972) could have permitted bad actors to deploy and execute firmware implants on the affected devices, the second batch (CVE-2022-1890, CVE-2022-1891, and CVE-2022-1892) could be weaponized to achieve arbitrary code execution and disable security features.

Lenovo said it does not intend to release fixes for CVE-2022-3432 owing to the fact that the model in question has reached end-of-life (EoL). Users of the other impacted devices are recommended to update their firmware to the latest version.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/11/new-uefi-firmware-flaws-reported-in.html