CVE-2022-40137
MEDIUMCVSS 6.7/10EPSS 0.23%
Last modified
CVE-2022-40137 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Lenovo | Ideacentre C5-14imb05 Firmware | o4hkt3aa | — |
| Lenovo | Ideacentre E96z Firmware | m26kt24a | — |
| Lenovo | Ideacentre 3 07iab7 Firmware | m49kt1da | — |
| Lenovo | Ideacentre 3-07imb05 Firmware | m2vkt1fa | — |
| Lenovo | Ideacentre 5 14iab7 Firmware | m42kt40a | — |
| Lenovo | Ideacentre 5-14acn6 Firmware | o5ekt23a | — |
| Lenovo | Ideacentre 5-14imb05 Firmware | o4hkt3aa | — |
| Lenovo | Ideacentre 5-14iob6 Firmware | m3gkt38a | — |
| Lenovo | Ideacentre Aio 3-22ada6 Firmware | o5ckt24a | — |
| Lenovo | Ideacentre Aio 3-22iil5 Firmware | o56kt22a | — |
| Lenovo | Ideacentre Aio 3-22itl6 Firmware | o5akt31a | — |
| Lenovo | Ideacentre Aio 3-24ada6 Firmware | o5ckt24a | — |
| Lenovo | Ideacentre Aio 3-24alc6 Firmware | o5bkt24a | — |
| Lenovo | Ideacentre Aio 3-24iil5 Firmware | o56kt22a | — |
| Lenovo | Ideacentre Aio 3-24itl6 Firmware | o5akt31a | — |
| Lenovo | Ideacentre Aio 3-27alc6 Firmware | o5bkt24a | — |
| Lenovo | Ideacentre Aio 3-27itl6 Firmware | o5akt31a | — |
| Lenovo | Ideacentre G5-14imb05 Firmware | o4hkt3aa | — |
| Lenovo | Ideacentre Gaming 5 17acn7 Firmware | o5ekt23a | — |
| Lenovo | Ideacentre Gaming 5 17iab7 Firmware | m42kt40a | — |
| Lenovo | Ideacentre Gaming 5-14acn6 Firmware | o5ekt23a | — |
| Lenovo | Ideacentre Gaming 5-14iob6 Firmware | m3gkt38a | — |
| Lenovo | Ideacentre Mini 5-01imh05 Firmware | o4ekt17a | — |
| Lenovo | Legion C530-19icb Firmware | o4bkt21a | — |
| Lenovo | Legion T5-26iob6 Firmware | o54kt20a | — |
| Lenovo | Legion T5-28icb05 Firmware | o4bkt21a | — |
| Lenovo | Legion T530-28apr Firmware | o4gkt17a | — |
| Lenovo | Legion T530-28icb Firmware | o4bkt21a | — |
| Lenovo | Legion T7-34imz5 Firmware | o4lkt1fa | — |
| Lenovo | Legion T7-34imz5 Firmware | o5fkt14a | — |
| Lenovo | Ideacentre M60e Tiny Firmware | m3skt21a | — |
| Lenovo | Ideacentre M625q Firmware | m1wkt46a | — |
| Lenovo | Ideacentre M630e Firmware | m28kt39a | — |
| Lenovo | Ideacentre M700 Tiny Firmware | fwktbfa | — |
| Lenovo | Ideacentre M70a Firmware | m2skt26a | — |
| Lenovo | Ideacentre M70a Gen 2 Firmware | m3nkt21a | — |
| Lenovo | Ideacentre M70a Gen 3 Firmware | m4ekt18a | — |
| Lenovo | Ideacentre M70c Firmware | m2vkt1fa | — |
| Lenovo | Ideacentre M70q Firmware | m2wkt55a | — |
| Lenovo | Ideacentre M70q Gen 2 Firmware | m3jkt35a | — |
| Lenovo | Ideacentre M70q Gen 3 Firmware | m43kt16a | — |
| Lenovo | Ideacentre M70s Firmware | m2tkt50a | — |
| Lenovo | Ideacentre M70s Gen 3 Firmware | m41kt2da | — |
| Lenovo | Ideacentre M70t Firmware | m2tkt50a | — |
| Lenovo | Ideacentre M70t Gen 3 Firmware | m41kt2da | — |
| Lenovo | Ideacentre M710e Firmware | m1zkt39a | — |
| Lenovo | Ideacentre M710q Firmware | m1akt56a | — |
| Lenovo | Ideacentre M710s Firmware | m16kt69a | — |
| Lenovo | Ideacentre M710t Firmware | m16kt69a | — |
| Lenovo | Ideacentre M715q 2nd Gen Firmware | m1xkt58a | — |
Showing 50 of 296 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-94953Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-94953Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-40137?
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
How severe is CVE-2022-40137?
CVE-2022-40137 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.23% probability of exploitation in the next 30 days.
How do I fix CVE-2022-40137?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2022-40137?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
