CVE-2022-1107

MEDIUMCVSS 6.7/10EPSS 0.25%

Last modified

CVE-2022-1107 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.

Description

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.25%

16.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoThinkpad 11e Firmware< n15et78w
LenovoThinkpad Helix Firmware< n17eta8w
LenovoThinkpad L560 Firmware< n1het85w
LenovoThinkpad L570 Firmware< n1xet65w
LenovoThinkpad P50s Firmware< n1ket46w
LenovoThinkpad P51s Firmware< n1vet50w
LenovoThinkpad P52s Firmware< n27et36w
LenovoThinkpad S540 Firmware< gpet80ww
LenovoThinkpad T550 Firmware< n11et50w
LenovoThinkpad T560 Firmware< n1ket46w
LenovoThinkpad T570 Firmware< n1vet50w
LenovoThinkpad T580 Firmware< n27et36w
LenovoThinkpad X1 Tablet Gen 1 Firmware< n1let86w
LenovoThinkpad X1 Tablet Gen 2 Firmware< n1oet50w
LenovoThinkpad W540 Firmware< gnet92ww
LenovoThinkpad W541 Firmware< gnet92ww
LenovoThinkpad W550s Firmware< n11et50w
LenovoThinkpad X1 Carbon 3rd Gen Firmware< n14et52w
LenovoThinkpad X1 Carbon 4th Gen Firmware< n1fet70w
LenovoThinkpad X1 Carbon 5th Gen Kabylake Firmware< n1met55w
LenovoThinkpad X1 Carbon 5th Gen Skylake Firmware< n1met55w
LenovoThinkpad X1 Yoga Firmware< n1fet70w
LenovoThinkpad X1 Yoga Gen 2 Firmware< n1net47w
LenovoThinkpad X1 Yoga Gen 3 Firmware< n25et50w
LenovoThinkpad X250 Firmware< n10et58w
LenovoThinkpad X280 Firmware< n20et44w
LenovoThinkpad X390 Firmware< n2let60w
LenovoThinkpad 11e Yoga Firmware< n15et78w
LenovoThinkpad Yoga 15 Firmware< n19et61w
LenovoThinkpad Yoga 260 Firmware< n1get98w

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-1107?
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
How severe is CVE-2022-1107?
CVE-2022-1107 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.25% probability of exploitation in the next 30 days.
How do I fix CVE-2022-1107?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-1107?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST