Vulnerability Description
In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Power Management | 1.67.12.19 |
| Lenovo | Thinkpad X1 Carbon 5 | - |
References
- https://support.lenovo.com/us/en/product_security/LEN-14440Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-14440Vendor Advisory
FAQ
What is CVE-2017-3741?
CVE-2017-3741 is a vulnerability with a CVSS score of 3.3 (LOW). In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon...
How severe is CVE-2017-3741?
CVE-2017-3741 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-3741?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Power Management, Lenovo Thinkpad X1 Carbon 5.