CVE-2016-8224

UnknownEPSS 0.30%

Last modified

CVE-2016-8224 is a vulnerability of currently unknown severity. A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.

Description

A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.

Metrics

EPSS Probability
0.30%

21.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoBiosAll versions
LenovoNotebook 110 14ibr BiosAll versions
LenovoNotebook 110 15ibr BiosAll versions
LenovoNotebook B70 80 BiosAll versions
LenovoNotebook E31 80 BiosAll versions
LenovoNotebook E40 80 BiosAll versions
LenovoNotebook E41 80 BiosAll versions
LenovoNotebook E51 80 BiosAll versions
LenovoNotebook G40 80 BiosAll versions
LenovoNotebook G50 80 BiosAll versions
LenovoNotebook G50 80 Touch BiosAll versions
LenovoNotebook Ideapad 300 14ibr BiosAll versions
LenovoNotebook Ideapad 300 14isk BiosAll versions
LenovoNotebook Ideapad 300 15ibr BiosAll versions
LenovoNotebook Ideapad 300 15isk BiosAll versions
LenovoNotebook Ideapad 300 17isk BiosAll versions
LenovoNotebook Ideapad 510s 12isk BiosAll versions
LenovoNotebook K21 80 BiosAll versions
LenovoNotebook K41 80 BiosAll versions
LenovoNotebook Miix 710 12ikb BiosAll versions
LenovoNotebook Xiaoxin Air 12 BiosAll versions
LenovoNotebook Yoga 510 14isk BiosAll versions
LenovoNotebook Yoga 510 15isk BiosAll versions
LenovoNotebook Yoga 710 11ikb BiosAll versions
LenovoNotebook Yoga 710 11isk BiosAll versions
LenovoNotebook Yoga 900 13isk BiosAll versions
LenovoNotebook Yoga 900s 12isk BiosAll versions
LenovoThinkserver Ts150 BiosAll versions
LenovoThinkserver Ts450 BiosAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-8224?
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.
How severe is CVE-2016-8224?
Severity scoring for CVE-2016-8224 is pending analysis. The EPSS model estimates a 0.30% probability of exploitation in the next 30 days.
How do I fix CVE-2016-8224?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-8224?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST