CVE-2021-3719

MEDIUMCVSS 6.7/10EPSS 0.24%

Last modified

CVE-2021-3719 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.

Description

A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.24%

15.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoThinkcentre E93 Firmware< fbktdfa
LenovoThinkcentre M600 Firmware< m00kt65a
LenovoThinkcentre M700 Tiny Firmware< fwktb9a
LenovoThinkcentre M73 Firmware< fhkt86a
LenovoThinkcentre M73p Firmware< fbktdfa
LenovoThinkcentre M800 Firmware< fwktb9a
LenovoThinkcentre M818z Firmware< m1ekt23a
LenovoThinkcentre M83 Firmware< fbktdfa
LenovoThinkcentre M900 Firmware< fwktb9a
LenovoThinkcentre M900x Firmware< fwktb9a
LenovoThinkcentre M93 Firmware< fbktdfa
LenovoThinkcentre M93p Firmware< fbktdfa
LenovoThinkcentre M4500q Firmware< fhkt86a
LenovoThinkcentre M6500t\/S Firmware< fbktdfa
LenovoThinkcentre M8500t\/S Firmware< fbktdfa
LenovoThinkcentre X1 Firmware< m0hkt50a
LenovoThinkstation P300 Firmware< fbktdfa
LenovoThinkstation P500 Firmware< a4ktaba
LenovoThinkstation P700 Firmware< a5ktaba
LenovoThinkstation P900 Firmware< a6ktaba

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-3719?
A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.
How severe is CVE-2021-3719?
CVE-2021-3719 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3719?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-3719?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST