VulnerabilityModified
CVE-2023-34419
A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
MEDIUM 6.7EPSS 0.19%
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.19% probability · 9th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- lenovo/legion 5 pro 16iah7h firmware · lenovo/legion 5 pro 16iah7 firmware · lenovo/legion 5 pro 16arh7 firmware · lenovo/legion 5 pro 16arh7h firmware · lenovo/legion 5 15arh7 firmware · lenovo/legion 5 15arh7h firmware · lenovo/legion 5 15iah7h firmware · lenovo/legion 5 15iah7 firmware · lenovo/legion 5 pro-16ach6 firmware · lenovo/legion 5 pro-16ach6h firmware · lenovo/legion 5 pro-16ith6 firmware · lenovo/legion 5 pro-16ith6h firmware · lenovo/legion 5-15ach6 firmware · lenovo/legion 5-15ach6a firmware · lenovo/legion 5-15ach6h firmware · lenovo/legion 5-15ith6 firmware · lenovo/legion 5-15ith6h firmware · lenovo/legion 5-17ach6 firmware · lenovo/legion 5-17ach6h firmware · lenovo/legion 5-17ith6 firmware · +10 more
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-134879Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-134879Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.