Vulnerability Description
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Ideacentre C5-14Imb05 Firmware | o4hkt3aa |
| Lenovo | Ideacentre C5-14Imb05 | - |
| Lenovo | Ideacentre E96Z Firmware | m26kt24a |
| Lenovo | Ideacentre E96Z | - |
| Lenovo | Ideacentre 3 07Iab7 Firmware | m49kt1da |
| Lenovo | Ideacentre 3 07Iab7 | - |
| Lenovo | Ideacentre 3-07Imb05 Firmware | m2vkt1fa |
| Lenovo | Ideacentre 3-07Imb05 | - |
| Lenovo | Ideacentre 5 14Iab7 Firmware | m42kt40a |
| Lenovo | Ideacentre 5 14Iab7 | - |
| Lenovo | Ideacentre 5-14Acn6 Firmware | o5ekt23a |
| Lenovo | Ideacentre 5-14Acn6 | - |
| Lenovo | Ideacentre 5-14Imb05 Firmware | o4hkt3aa |
| Lenovo | Ideacentre 5-14Imb05 | - |
| Lenovo | Ideacentre 5-14Iob6 Firmware | m3gkt38a |
| Lenovo | Ideacentre 5-14Iob6 | - |
| Lenovo | Ideacentre Aio 3-22Ada6 Firmware | o5ckt24a |
| Lenovo | Ideacentre Aio 3-22Ada6 | - |
| Lenovo | Ideacentre Aio 3-22Iil5 Firmware | o56kt22a |
| Lenovo | Ideacentre Aio 3-22Iil5 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-94953Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-94953Vendor Advisory
FAQ
What is CVE-2022-40137?
CVE-2022-40137 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
How severe is CVE-2022-40137?
CVE-2022-40137 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40137?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Ideacentre C5-14Imb05 Firmware, Lenovo Ideacentre C5-14Imb05, Lenovo Ideacentre E96Z Firmware, Lenovo Ideacentre E96Z, Lenovo Ideacentre 3 07Iab7 Firmware.