CVE-2021-4212
Last modified
CVE-2021-4212 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | C340-14iml Firmware | All versions |
| Lenovo | C340-15iml Firmware | All versions |
| Lenovo | D330-10igm Firmware | All versions |
| Lenovo | Duet 3-10igl5 Firmware | All versions |
| Lenovo | E41-50 Firmware | All versions |
| Lenovo | Flex-14iml Firmware | All versions |
| Lenovo | Flex-15iml Firmware | All versions |
| Lenovo | Ideapad 3-14are05 Firmware | All versions |
| Lenovo | Ideapad 3-15are05 Firmware | All versions |
| Lenovo | Ideapad 3-17are05 Firmware | All versions |
| Lenovo | Ideapad 5-14alc05 Firmware | All versions |
| Lenovo | Ideapad 5-14are05 Firmware | All versions |
| Lenovo | Ideapad 5-15itl05 Firmware | All versions |
| Lenovo | Ideapad 5 Pro-14acn6 Firmware | All versions |
| Lenovo | Ideapad 5 Pro-14itl6 Firmware | All versions |
| Lenovo | Ideapad 5 Pro-16ihu6 Firmware | All versions |
| Lenovo | Ideapad Creator 5-15imh05 Firmware | All versions |
| Lenovo | Ideapad Gaming 3-15ach6 Firmware | All versions |
| Lenovo | Ideapad Gaming 3-15arh05 Firmware | All versions |
| Lenovo | Ideapad Gaming 3-15imh05 Firmware | All versions |
| Lenovo | L340-15irh Firmware | All versions |
| Lenovo | L340-15iwl Firmware | All versions |
| Lenovo | L340-15iwl Touch Firmware | All versions |
| Lenovo | L340-17irh Firmware | All versions |
| Lenovo | L340-17iwl Firmware | All versions |
| Lenovo | Legion Y540-15irh Firmware | All versions |
| Lenovo | Legion Y540-15irh-Pg0 Firmware | All versions |
| Lenovo | Legion Y540-17irh Firmware | All versions |
| Lenovo | Legion Y540-17irh-Pg0 Firmware | All versions |
| Lenovo | Legion Y545 Firmware | All versions |
| Lenovo | Legion Y545-Pg0 Firmware | All versions |
| Lenovo | Legion Y7000-2019 Firmware | All versions |
| Lenovo | Legion Y7000-2019-Pg0 Firmware | All versions |
| Lenovo | S340-13iml Firmware | All versions |
| Lenovo | S340-14api Firmware | All versions |
| Lenovo | S340-14iml Firmware | All versions |
| Lenovo | S340-15api Firmware | All versions |
| Lenovo | S340-15api Touch Firmware | All versions |
| Lenovo | S340-15iml Firmware | All versions |
| Lenovo | S540-14iml Firmware | All versions |
| Lenovo | S540-14iml Touch Firmware | All versions |
| Lenovo | S540-15iml Firmware | All versions |
| Lenovo | Slim 7-14are05 Firmware | All versions |
| Lenovo | Slim 7-14itl05 Firmware | All versions |
| Lenovo | Slim 7-15iil05 Firmware | All versions |
| Lenovo | Slim 7-15imh05 Firmware | All versions |
| Lenovo | Slim 7-15itl05 Firmware | All versions |
| Lenovo | Thinkbook 13x Itg Firmware | All versions |
| Lenovo | Thinkbook 14 G3 Itl Firmware | All versions |
| Lenovo | Thinkbook Plus G2 Itg Firmware | All versions |
Showing 50 of 62 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-77639Patch, Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-77639Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-4212?
How severe is CVE-2021-4212?
How do I fix CVE-2021-4212?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-42114Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vul…8.3
- CVE-2021-42115Missing HTTPOnly flag in Web Applications operating on Busin…9.1
- CVE-2021-42116Incorrect Access Control in Web Applications operating on Bu…4.3
- CVE-2021-42117Insufficient Input Validation in Web Applications operating …5.4
- CVE-2021-42118Persistent Cross Site Scripting in Web Applications operatin…5.4
- CVE-2021-42119Persistent Cross Site Scripting in Web Applications operatin…5.4
- CVE-2021-42120Insufficient Input Validation in Web Applications operating …6.5
- CVE-2021-42121Insufficient Input Validation in Web Applications operating …4.3
- CVE-2021-42122Insufficient Input Validation in Web Applications operating …4.3
- CVE-2021-42123Unrestricted File Upload in Web Applications operating on Bu…8.8
- CVE-2021-42124An improper access control vulnerability exists in Ivanti Av…8.8
- CVE-2021-42125An unrestricted file upload vulnerability exists in Ivanti A…8.8
Are you affected by CVE-2021-4212?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
