MEDIUM · 6.7

CVE-2022-1107

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker ...

Vulnerability Description

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoThinkpad 11E Firmware< n15et78w
LenovoThinkpad 11E-
LenovoThinkpad Helix Firmware< n17eta8w
LenovoThinkpad Helix-
LenovoThinkpad L560 Firmware< n1het85w
LenovoThinkpad L560-
LenovoThinkpad L570 Firmware< n1xet65w
LenovoThinkpad L570-
LenovoThinkpad P50S Firmware< n1ket46w
LenovoThinkpad P50S-
LenovoThinkpad P51S Firmware< n1vet50w
LenovoThinkpad P51S-
LenovoThinkpad P52S Firmware< n27et36w
LenovoThinkpad P52S-
LenovoThinkpad S540 Firmware< gpet80ww
LenovoThinkpad S540-
LenovoThinkpad T550 Firmware< n11et50w
LenovoThinkpad T550-
LenovoThinkpad T560 Firmware< n1ket46w
LenovoThinkpad T560-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-1107?

CVE-2022-1107 is a vulnerability with a CVSS score of 6.7 (MEDIUM). During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker ...

How severe is CVE-2022-1107?

CVE-2022-1107 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-1107?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkpad 11E Firmware, Lenovo Thinkpad 11E, Lenovo Thinkpad Helix Firmware, Lenovo Thinkpad Helix, Lenovo Thinkpad L560 Firmware.