CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code. | 6.7 |
Moyen |
||
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. | 6.7 |
Moyen |
||
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. | 6.8 |
Moyen |
||
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code. | 6.8 |
Moyen |