CVE-2017-3753
Last modified
CVE-2017-3753 is a vulnerability of currently unknown severity. A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Ideacentre 300-20ish Firmware | All versions |
| Lenovo | Ideacentre 300s-11ish Firmware | All versions |
| Lenovo | Ideacentre 510s-08ish Firmware | All versions |
| Lenovo | Ideacentre 700 Firmware | All versions |
| Lenovo | 63 Firmware | fckt78a |
| Lenovo | H50-30g Firmware | fckt78a |
| Lenovo | M4500 Firmware | fckt78a |
| Lenovo | M4500 Id Firmware | fckt78a |
| Lenovo | M4550 Id Firmware | fckt78a |
| Lenovo | S500 Firmware | m0kkt24a |
| Lenovo | V320-15iap Firmware | All versions |
| Lenovo | Thinkcentre E73 Firmware | fckt78a |
| Lenovo | Thinkcentre E73s Firmware | fckt78a |
| Lenovo | Thinkcentre E74 Firmware | m05kt54a |
| Lenovo | Thinkcentre E74s Firmware | m05kt54a |
| Lenovo | Thinkcentre E75 T\/S Firmware | All versions |
| Lenovo | Thinkcentre E79 Firmware | m0lkt12a |
| Lenovo | Thinkcentre E93 Firmware | fbktc5a |
| Lenovo | Thinkcentre M4500k Firmware | fckt78a |
| Lenovo | Thinkcentre M4500q Firmware | fhkt66a |
| Lenovo | Thinkcentre M4500t\/S Firmware | fckt78a |
| Lenovo | Thinkcentre M4600t\/S Firmware | m05kt54a |
| Lenovo | Thinkcentre M600 Firmware | m00kt44a |
| Lenovo | Thinkcentre M610 Firmware | All versions |
| Lenovo | Thinkcentre M6500t\/S Firmware | fbktc5a |
| Lenovo | Thinkcentre M6600 Firmware | fwkt39a |
| Lenovo | Thinkcentre M6600q Firmware | fwkt39a |
| Lenovo | Thinkcentre M6600t\/S Firmware | fwkt39a |
| Lenovo | Thinkcentre M700 Firmware | m05kt54a |
| Lenovo | Thinkcentre M710t\/S Firmware | All versions |
| Lenovo | Thinkcentre M715q Firmware | All versions |
| Lenovo | Thinkcentre M72e Firmware | f1kt71a |
| Lenovo | Thinkcentre M73 Firmware | fckt78a |
| Lenovo | Thinkcentre M73p Firmware | fbktc5a |
| Lenovo | Thinkcentre M79 Firmware | m0lkt12a |
| Lenovo | Thinkcentre M800 Firmware | fwkt39a |
| Lenovo | Thinkcentre M83 Firmware | fbktcga |
| Lenovo | Thinkcentre M8500t\/S Firmware | fbktc5a |
| Lenovo | Thinkcentre M8600t\/S Firmware | fwkt39a |
| Lenovo | Thinkcentre M900 Firmware | fwkt39a |
| Lenovo | Thinkcentre M910t\/S Firmware | All versions |
| Lenovo | Thinkcentre M910q Firmware | All versions |
| Lenovo | Thinkcentre M910x Firmware | All versions |
| Lenovo | Thinkcentre M92 Firmware | 9skt95a |
| Lenovo | Thinkcentre M92p Firmware | 9skt95a |
| Lenovo | Thinkcentre M93 Firmware | fbktc5a |
| Lenovo | Thinkcentre M93p Firmware | fbktc5a |
| Lenovo | Yangtian Afh110 Firmware | m05kt73a |
| Lenovo | Yangtian Afh81 Firmware | fckt80a |
| Lenovo | Yangtian Afq150 Firmware | fwkt57a |
Showing 50 of 111 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-14695Mitigation, Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-14695Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-3753?
How severe is CVE-2017-3753?
How do I fix CVE-2017-3753?
Are you affected by CVE-2017-3753?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
