CVE-2017-3753
Last modified
CVE-2017-3753 is a vulnerability of currently unknown severity. A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Ideacentre 300-20ish Firmware | All versions |
| Lenovo | Ideacentre 300s-11ish Firmware | All versions |
| Lenovo | Ideacentre 510s-08ish Firmware | All versions |
| Lenovo | Ideacentre 700 Firmware | All versions |
| Lenovo | 63 Firmware | fckt78a |
| Lenovo | H50-30g Firmware | fckt78a |
| Lenovo | M4500 Firmware | fckt78a |
| Lenovo | M4500 Id Firmware | fckt78a |
| Lenovo | M4550 Id Firmware | fckt78a |
| Lenovo | S500 Firmware | m0kkt24a |
| Lenovo | V320-15iap Firmware | All versions |
| Lenovo | Thinkcentre E73 Firmware | fckt78a |
| Lenovo | Thinkcentre E73s Firmware | fckt78a |
| Lenovo | Thinkcentre E74 Firmware | m05kt54a |
| Lenovo | Thinkcentre E74s Firmware | m05kt54a |
| Lenovo | Thinkcentre E75 T\/S Firmware | All versions |
| Lenovo | Thinkcentre E79 Firmware | m0lkt12a |
| Lenovo | Thinkcentre E93 Firmware | fbktc5a |
| Lenovo | Thinkcentre M4500k Firmware | fckt78a |
| Lenovo | Thinkcentre M4500q Firmware | fhkt66a |
| Lenovo | Thinkcentre M4500t\/S Firmware | fckt78a |
| Lenovo | Thinkcentre M4600t\/S Firmware | m05kt54a |
| Lenovo | Thinkcentre M600 Firmware | m00kt44a |
| Lenovo | Thinkcentre M610 Firmware | All versions |
| Lenovo | Thinkcentre M6500t\/S Firmware | fbktc5a |
| Lenovo | Thinkcentre M6600 Firmware | fwkt39a |
| Lenovo | Thinkcentre M6600q Firmware | fwkt39a |
| Lenovo | Thinkcentre M6600t\/S Firmware | fwkt39a |
| Lenovo | Thinkcentre M700 Firmware | m05kt54a |
| Lenovo | Thinkcentre M710t\/S Firmware | All versions |
| Lenovo | Thinkcentre M715q Firmware | All versions |
| Lenovo | Thinkcentre M72e Firmware | f1kt71a |
| Lenovo | Thinkcentre M73 Firmware | fckt78a |
| Lenovo | Thinkcentre M73p Firmware | fbktc5a |
| Lenovo | Thinkcentre M79 Firmware | m0lkt12a |
| Lenovo | Thinkcentre M800 Firmware | fwkt39a |
| Lenovo | Thinkcentre M83 Firmware | fbktcga |
| Lenovo | Thinkcentre M8500t\/S Firmware | fbktc5a |
| Lenovo | Thinkcentre M8600t\/S Firmware | fwkt39a |
| Lenovo | Thinkcentre M900 Firmware | fwkt39a |
| Lenovo | Thinkcentre M910t\/S Firmware | All versions |
| Lenovo | Thinkcentre M910q Firmware | All versions |
| Lenovo | Thinkcentre M910x Firmware | All versions |
| Lenovo | Thinkcentre M92 Firmware | 9skt95a |
| Lenovo | Thinkcentre M92p Firmware | 9skt95a |
| Lenovo | Thinkcentre M93 Firmware | fbktc5a |
| Lenovo | Thinkcentre M93p Firmware | fbktc5a |
| Lenovo | Yangtian Afh110 Firmware | m05kt73a |
| Lenovo | Yangtian Afh81 Firmware | fckt80a |
| Lenovo | Yangtian Afq150 Firmware | fwkt57a |
Showing 50 of 111 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-14695Mitigation, Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-14695Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-3753?
How severe is CVE-2017-3753?
How do I fix CVE-2017-3753?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-3747Privilege escalation vulnerability in Lenovo Nerve Center fo…
- CVE-2017-3748On Lenovo VIBE mobile phones, improper access controls on th…
- CVE-2017-3749On Lenovo VIBE mobile phones, the Idea Friend Android applic…
- CVE-2017-3750On Lenovo VIBE mobile phones, the Lenovo Security Android ap…
- CVE-2017-3751An unquoted service path vulnerability was identified in the…
- CVE-2017-3752An industry-wide vulnerability has been identified in the im…
- CVE-2017-3754Some Lenovo brand notebook systems do not have write protect…
- CVE-2017-3755Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2017-3756A privilege escalation vulnerability was identified in Lenov…
- CVE-2017-3757An unquoted service path vulnerability was identified in the…
- CVE-2017-3758Improper access controls on several Android components in th…
- CVE-2017-3759The Lenovo Service Framework Android application accepts som…
Are you affected by CVE-2017-3753?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
