SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-48188

A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.

HIGH 7.8EPSS 0.19%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.19% probability · 9th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
lenovo/ideacentre aio 3 21itl7 firmware · lenovo/ideacentre aio 3-22itl6 firmware · lenovo/ideacentre aio 3-24itl6 firmware · lenovo/ideacentre aio 3-27itl6 firmware · lenovo/thinkcentre m720e firmware · lenovo/thinkcentre m720q firmware · lenovo/thinkcentre m720s firmware · lenovo/thinkcentre m720t firmware · lenovo/thinkcentre m725s firmware · lenovo/thinkcentre m75s gen 2 firmware · lenovo/thinkcentre m75t gen 2 firmware · lenovo/thinkcentre m920q firmware · lenovo/thinkcentre m920s firmware · lenovo/thinkcentre m920t firmware · lenovo/thinkcentre m920x firmware · lenovo/thinkcentre m920z firmware · lenovo/ideacentre 510s-07icb firmware · lenovo/ideacentre 510s-07ick firmware · lenovo/ideacentre 720-18apr firmware · lenovo/v30a-22itl firmware · +7 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.