MEDIUM · 6.7

CVE-2022-1892

A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

Vulnerability Description

A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Lenovo100E 2Nd Gen Firmware< frcn23ww
Lenovo100E 2Nd Gen-
Lenovo100W Gen 3 Firmware< gacn38ww
Lenovo100W Gen 3-
Lenovo13W Yoga Firmware< jacn31ww
Lenovo13W Yoga-
Lenovo14W Gen 2 Firmware< h0cn21ww
Lenovo14W Gen 2-
Lenovo300E 2Nd Gen Firmware< frcn23ww
Lenovo300E 2Nd Gen-
Lenovo300W Gen 3 Firmware< gacn38ww
Lenovo300W Gen 3-
Lenovo500W Gen 3 Firmware< g6cn40ww
Lenovo500W Gen 3-
Lenovo730S-13Iml Firmware< brcn20ww
Lenovo730S-13Iml-
LenovoFlex 3-11Ada05 Firmware< fpcn26ww
LenovoFlex 3-11Ada05-
LenovoFlex 5-14Alc05 Firmware< gjcn27ww
LenovoFlex 5-14Alc05-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-1892?

CVE-2022-1892 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

How severe is CVE-2022-1892?

CVE-2022-1892 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-1892?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo 100E 2Nd Gen Firmware, Lenovo 100E 2Nd Gen, Lenovo 100W Gen 3 Firmware, Lenovo 100W Gen 3, Lenovo 13W Yoga Firmware.