Vulnerability Description
A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Bios | - |
| Lenovo | Thinkpad 11E 3Rd Gen | - |
| Lenovo | Thinkpad 11E 4Th Gen | - |
| Lenovo | Thinkpad 11E 5Th Gen | - |
| Lenovo | Thinkpad 11E Yoga Gen 6 | - |
| Lenovo | Thinkpad 13 Gen 2 | - |
| Lenovo | Thinkpad E14 Gen 2 | - |
| Lenovo | Thinkpad E15 Gen 2 | - |
| Lenovo | Thinkpad L13 | - |
| Lenovo | Thinkpad L13 Gen 2 | - |
| Lenovo | Thinkpad L13 Yoga | - |
| Lenovo | Thinkpad L13 Yogo Gen 2 | - |
| Lenovo | Thinkpad L14 | - |
| Lenovo | Thinkpad L14 Gen 2 | - |
| Lenovo | Thinkpad L15 | - |
| Lenovo | Thinkpad L15 Gen 2 | - |
| Lenovo | Thinkpad L380 | - |
| Lenovo | Thinkpad L380 Yoga | - |
| Lenovo | Thinkpad L390 | - |
| Lenovo | Thinkpad L390 Yoga | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-65529Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-65529Vendor Advisory
FAQ
What is CVE-2021-3452?
CVE-2021-3452 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
How severe is CVE-2021-3452?
CVE-2021-3452 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3452?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Bios, Lenovo Thinkpad 11E 3Rd Gen, Lenovo Thinkpad 11E 4Th Gen, Lenovo Thinkpad 11E 5Th Gen, Lenovo Thinkpad 11E Yoga Gen 6.