CVE-2022-1107
Last modified
CVE-2022-1107 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkpad 11e Firmware | < n15et78w |
| Lenovo | Thinkpad Helix Firmware | < n17eta8w |
| Lenovo | Thinkpad L560 Firmware | < n1het85w |
| Lenovo | Thinkpad L570 Firmware | < n1xet65w |
| Lenovo | Thinkpad P50s Firmware | < n1ket46w |
| Lenovo | Thinkpad P51s Firmware | < n1vet50w |
| Lenovo | Thinkpad P52s Firmware | < n27et36w |
| Lenovo | Thinkpad S540 Firmware | < gpet80ww |
| Lenovo | Thinkpad T550 Firmware | < n11et50w |
| Lenovo | Thinkpad T560 Firmware | < n1ket46w |
| Lenovo | Thinkpad T570 Firmware | < n1vet50w |
| Lenovo | Thinkpad T580 Firmware | < n27et36w |
| Lenovo | Thinkpad X1 Tablet Gen 1 Firmware | < n1let86w |
| Lenovo | Thinkpad X1 Tablet Gen 2 Firmware | < n1oet50w |
| Lenovo | Thinkpad W540 Firmware | < gnet92ww |
| Lenovo | Thinkpad W541 Firmware | < gnet92ww |
| Lenovo | Thinkpad W550s Firmware | < n11et50w |
| Lenovo | Thinkpad X1 Carbon 3rd Gen Firmware | < n14et52w |
| Lenovo | Thinkpad X1 Carbon 4th Gen Firmware | < n1fet70w |
| Lenovo | Thinkpad X1 Carbon 5th Gen Kabylake Firmware | < n1met55w |
| Lenovo | Thinkpad X1 Carbon 5th Gen Skylake Firmware | < n1met55w |
| Lenovo | Thinkpad X1 Yoga Firmware | < n1fet70w |
| Lenovo | Thinkpad X1 Yoga Gen 2 Firmware | < n1net47w |
| Lenovo | Thinkpad X1 Yoga Gen 3 Firmware | < n25et50w |
| Lenovo | Thinkpad X250 Firmware | < n10et58w |
| Lenovo | Thinkpad X280 Firmware | < n20et44w |
| Lenovo | Thinkpad X390 Firmware | < n2let60w |
| Lenovo | Thinkpad 11e Yoga Firmware | < n15et78w |
| Lenovo | Thinkpad Yoga 15 Firmware | < n19et61w |
| Lenovo | Thinkpad Yoga 260 Firmware | < n1get98w |
References
- https://support.lenovo.com/us/en/product_security/LEN-84943Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-84943Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-1107?
How severe is CVE-2022-1107?
How do I fix CVE-2022-1107?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-1101A vulnerability was found in SourceCodester Royale Event Man…9.8
- CVE-2022-1102A vulnerability classified as problematic has been found in …6.1
- CVE-2022-1103The Advanced Uploader WordPress plugin through 4.2 allows an…8.8
- CVE-2022-1104The Popup Maker WordPress plugin before 1.16.5 does not sani…4.8
- CVE-2022-1105An improper access control vulnerability in GitLab CE/EE aff…4.3
- CVE-2022-1106use after free in mrb_vm_exec in GitHub repository mruby/mru…9.1
- CVE-2022-1108A potential vulnerability due to improper buffer validation …6.7
- CVE-2022-1109An incorrect default permissions vulnerability in Lenovo Ley…7.5
- CVE-2022-1110A buffer overflow vulnerability in Lenovo Smart Standby Driv…5.5
- CVE-2022-1111A business logic error in Project Import in GitLab CE/EE ver…2.7
- CVE-2022-1112The Autolinks WordPress plugin through 1.0.1 does not have C…5.4
- CVE-2022-1113The Flower Delivery by Florist One WordPress plugin through …4.8
Are you affected by CVE-2022-1107?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
