Vulnerability Description
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Bios | - |
| Lenovo | Notebook 110 14Ibr Bios | - |
| Lenovo | Notebook 110 15Ibr Bios | - |
| Lenovo | Notebook B70 80 Bios | - |
| Lenovo | Notebook E31 80 Bios | - |
| Lenovo | Notebook E40 80 Bios | - |
| Lenovo | Notebook E41 80 Bios | - |
| Lenovo | Notebook E51 80 Bios | - |
| Lenovo | Notebook G40 80 Bios | - |
| Lenovo | Notebook G50 80 Bios | - |
| Lenovo | Notebook G50 80 Touch Bios | - |
| Lenovo | Notebook Ideapad 300 14Ibr Bios | - |
| Lenovo | Notebook Ideapad 300 14Isk Bios | - |
| Lenovo | Notebook Ideapad 300 15Ibr Bios | - |
| Lenovo | Notebook Ideapad 300 15Isk Bios | - |
| Lenovo | Notebook Ideapad 300 17Isk Bios | - |
| Lenovo | Notebook Ideapad 510S 12Isk Bios | - |
| Lenovo | Notebook K21 80 Bios | - |
| Lenovo | Notebook K41 80 Bios | - |
| Lenovo | Notebook Miix 710 12Ikb Bios | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94595
- https://support.lenovo.com/us/en/solutions/LEN_9903Vendor Advisory
- http://www.securityfocus.com/bid/94595
- https://support.lenovo.com/us/en/solutions/LEN_9903Vendor Advisory
FAQ
What is CVE-2016-8224?
CVE-2016-8224 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Manageme...
How severe is CVE-2016-8224?
CVE-2016-8224 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8224?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Bios, Lenovo Notebook 110 14Ibr Bios, Lenovo Notebook 110 15Ibr Bios, Lenovo Notebook B70 80 Bios, Lenovo Notebook E31 80 Bios.