VulnerabilityModified
CVE-2017-3756
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17.
HIGH 7.8EPSS 0.38%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Affected
- lenovo/thinkpad 10 ella 2 bios · lenovo/thinkpad 11e beema bios · lenovo/thinkpad 11e braswell bios · lenovo/thinkpad 11e broadwell bios · lenovo/thinkpad 11e skylake bios · lenovo/thinkpad 13e bios · lenovo/thinkpad e450 bios · lenovo/thinkpad e450c bios · lenovo/thinkpad e455 bios · lenovo/thinkpad e460 bios · lenovo/thinkpad e465 bios · lenovo/thinkpad e550 bios · lenovo/thinkpad e550c bios · lenovo/thinkpad e555 bios · lenovo/thinkpad e560 bios · lenovo/thinkpad e565 bios · lenovo/thinkpad edge e440 bios · lenovo/thinkpad edge e445 bios · lenovo/thinkpad edge e540 bios · lenovo/thinkpad edge e545 bios · +40 more
- Source
- psirt@lenovo.com
References
- http://www.securityfocus.com/bid/100305Third Party Advisory, VDB Entry
- https://support.lenovo.com/us/en/product_security/LEN-15765Vendor Advisory
- http://www.securityfocus.com/bid/100305Third Party Advisory, VDB Entry
- https://support.lenovo.com/us/en/product_security/LEN-15765Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.