CVE-2017-3756

UnknownEPSS 0.38%

Last modified

CVE-2017-3756 is a vulnerability of currently unknown severity. A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.

Description

A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.

Metrics

EPSS Probability
0.38%

29.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
LenovoThinkpad 10 Ella 2 BiosAll versions
LenovoThinkpad 11e Beema BiosAll versions
LenovoThinkpad 11e Braswell BiosAll versions
LenovoThinkpad 11e Broadwell BiosAll versions
LenovoThinkpad 11e Skylake BiosAll versions
LenovoThinkpad 13e BiosAll versions
LenovoThinkpad E450 BiosAll versions
LenovoThinkpad E450c BiosAll versions
LenovoThinkpad E455 BiosAll versions
LenovoThinkpad E460 BiosAll versions
LenovoThinkpad E465 BiosAll versions
LenovoThinkpad E550 BiosAll versions
LenovoThinkpad E550c BiosAll versions
LenovoThinkpad E555 BiosAll versions
LenovoThinkpad E560 BiosAll versions
LenovoThinkpad E565 BiosAll versions
LenovoThinkpad Edge E440 BiosAll versions
LenovoThinkpad Edge E445 BiosAll versions
LenovoThinkpad Edge E540 BiosAll versions
LenovoThinkpad Edge E545 BiosAll versions
LenovoThinkpad Helix 20cg BiosAll versions
LenovoThinkpad Helix 20ch BiosAll versions
LenovoThinkpad L440 BiosAll versions
LenovoThinkpad L450 BiosAll versions
LenovoThinkpad L460 BiosAll versions
LenovoThinkpad L540 BiosAll versions
LenovoThinkpad L560 BiosAll versions
LenovoThinkpad P50 BiosAll versions
LenovoThinkpad P50s BiosAll versions
LenovoThinkpad P70 BiosAll versions
LenovoThinkpad S1 Yoga 12 BiosAll versions
LenovoThinkpad S1 Yoga Non Vpro BiosAll versions
LenovoThinkpad S1 Yoga Vpro BiosAll versions
LenovoThinkpad S3 S440 BiosAll versions
LenovoThinkpad S3 Yoga 14 BiosAll versions
LenovoThinkpad S5 E560p BiosAll versions
LenovoThinkpad S5 Yoga 15 BiosAll versions
LenovoThinkpad S540 BiosAll versions
LenovoThinkpad T440 BiosAll versions
LenovoThinkpad T440p BiosAll versions
LenovoThinkpad T440s BiosAll versions
LenovoThinkpad T440u BiosAll versions
LenovoThinkpad T450 BiosAll versions
LenovoThinkpad T450s BiosAll versions
LenovoThinkpad T460 BiosAll versions
LenovoThinkpad T460p BiosAll versions
LenovoThinkpad T460s BiosAll versions
LenovoThinkpad T540 BiosAll versions
LenovoThinkpad T540p BiosAll versions
LenovoThinkpad T550 BiosAll versions

Showing 50 of 148 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-3756?
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.
How severe is CVE-2017-3756?
Severity scoring for CVE-2017-3756 is pending analysis. The EPSS model estimates a 0.38% probability of exploitation in the next 30 days.
How do I fix CVE-2017-3756?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-3756?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST