Vulnerability Description
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Ideacentre 300-20Ish Firmware | - |
| Lenovo | Ideacentre 300-20Ish | - |
| Lenovo | Ideacentre 300S-11Ish Firmware | - |
| Lenovo | Ideacentre 300S-11Ish | - |
| Lenovo | Ideacentre 510S-08Ish Firmware | - |
| Lenovo | Ideacentre 510S-08Ish | - |
| Lenovo | Ideacentre 700 Firmware | - |
| Lenovo | Ideacentre 700 | - |
| Lenovo | 63 Firmware | fckt78a |
| Lenovo | 63 | - |
| Lenovo | H50-30G Firmware | fckt78a |
| Lenovo | H50-30G | - |
| Lenovo | M4500 Firmware | fckt78a |
| Lenovo | M4500 | - |
| Lenovo | M4500 Id Firmware | fckt78a |
| Lenovo | M4500 Id | - |
| Lenovo | M4550 Id Firmware | fckt78a |
| Lenovo | M4550 Id | - |
| Lenovo | S500 Firmware | m0kkt24a |
| Lenovo | S500 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-14695MitigationVendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-14695MitigationVendor Advisory
FAQ
What is CVE-2017-3753?
CVE-2017-3753 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with adm...
How severe is CVE-2017-3753?
CVE-2017-3753 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-3753?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Ideacentre 300-20Ish Firmware, Lenovo Ideacentre 300-20Ish, Lenovo Ideacentre 300S-11Ish Firmware, Lenovo Ideacentre 300S-11Ish, Lenovo Ideacentre 510S-08Ish Firmware.