SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-34419

A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

MEDIUM 6.7EPSS 0.19%

Does this matter?

Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.

Description

A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.19% probability · 9th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
lenovo/legion 5 pro 16iah7h firmware · lenovo/legion 5 pro 16iah7 firmware · lenovo/legion 5 pro 16arh7 firmware · lenovo/legion 5 pro 16arh7h firmware · lenovo/legion 5 15arh7 firmware · lenovo/legion 5 15arh7h firmware · lenovo/legion 5 15iah7h firmware · lenovo/legion 5 15iah7 firmware · lenovo/legion 5 pro-16ach6 firmware · lenovo/legion 5 pro-16ach6h firmware · lenovo/legion 5 pro-16ith6 firmware · lenovo/legion 5 pro-16ith6h firmware · lenovo/legion 5-15ach6 firmware · lenovo/legion 5-15ach6a firmware · lenovo/legion 5-15ach6h firmware · lenovo/legion 5-15ith6 firmware · lenovo/legion 5-15ith6h firmware · lenovo/legion 5-17ach6 firmware · lenovo/legion 5-17ach6h firmware · lenovo/legion 5-17ith6 firmware · +10 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.