SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-1107

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for…

MEDIUM 6.7EPSS 0.27%

Does this matter?

Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.

Description

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.27% probability · 19th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-269
Affected
lenovo/thinkpad 11e firmware · lenovo/thinkpad helix firmware · lenovo/thinkpad l560 firmware · lenovo/thinkpad l570 firmware · lenovo/thinkpad p50s firmware · lenovo/thinkpad p51s firmware · lenovo/thinkpad p52s firmware · lenovo/thinkpad s540 firmware · lenovo/thinkpad t550 firmware · lenovo/thinkpad t560 firmware · lenovo/thinkpad t570 firmware · lenovo/thinkpad t580 firmware · lenovo/thinkpad x1 tablet gen 1 firmware · lenovo/thinkpad x1 tablet gen 2 firmware · lenovo/thinkpad w540 firmware · lenovo/thinkpad w541 firmware · lenovo/thinkpad w550s firmware · lenovo/thinkpad x1 carbon 3rd gen firmware · lenovo/thinkpad x1 carbon 4th gen firmware · lenovo/thinkpad x1 carbon 5th gen kabylake firmware · +10 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.