PT-2024-2539 · Lenovo · Lenovo Notebook

Published

2024-03-12

·

Updated

2024-04-08

·

CVE-2023-5912

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lenovo Notebook products (affected versions not specified)
Description A potential memory leakage vulnerability was reported in some Lenovo Notebook products. This issue may allow a local attacker with elevated privileges to write to NVRAM variables. The vulnerability is related to the System Management Mode (SMM) of the Lenovo Notebook products' firmware and is associated with insufficient input validation, which could allow an attacker to elevate their privileges and execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-02525
CVE-2023-5912

Affected Products

Lenovo Notebook