PT-2024-2539 · Lenovo · Lenovo Notebook
Published
2024-03-12
·
Updated
2024-04-08
·
CVE-2023-5912
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Lenovo Notebook products (affected versions not specified)
Description
A potential memory leakage vulnerability was reported in some Lenovo Notebook products. This issue may allow a local attacker with elevated privileges to write to NVRAM variables. The vulnerability is related to the System Management Mode (SMM) of the Lenovo Notebook products' firmware and is associated with insufficient input validation, which could allow an attacker to elevate their privileges and execute arbitrary code.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lenovo Notebook