CVE-2022-48188

HIGHCVSS 7.8/10EPSS 0.19%

Last modified

CVE-2022-48188 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.

Description

A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.19%

9.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoIdeacentre Aio 3 21itl7 Firmware< o5akt33
LenovoIdeacentre Aio 3-22itl6 Firmware< o5akt33
LenovoIdeacentre Aio 3-24itl6 Firmware< o5akt33
LenovoIdeacentre Aio 3-27itl6 Firmware< o5akt33
LenovoThinkcentre M720e Firmware< m1zkt40a
LenovoThinkcentre M720q Firmware< m1ukt70a
LenovoThinkcentre M720s Firmware< m1ukt70a
LenovoThinkcentre M720t Firmware< m1ukt70a
LenovoThinkcentre M725s Firmware< m25kt63a
LenovoThinkcentre M75s Gen 2 Firmware< m46kt30a
LenovoThinkcentre M75s Gen 2 Firmware< m3bkt30a
LenovoThinkcentre M75t Gen 2 Firmware< m46kt30a
LenovoThinkcentre M75t Gen 2 Firmware< m3akt4ca
LenovoThinkcentre M920q Firmware< m1ukt70a
LenovoThinkcentre M920s Firmware< m1ukt70a
LenovoThinkcentre M920t Firmware< m1ukt70a
LenovoThinkcentre M920x Firmware< m1ukt70a
LenovoThinkcentre M920z Firmware< m1mkt55a
LenovoIdeacentre 510s-07icb Firmware< m22kt48a
LenovoIdeacentre 510s-07icb Firmware< m22kt49a
LenovoIdeacentre 510s-07ick Firmware< m30kt28a
LenovoIdeacentre 510s-07ick Firmware< m1zkt40a
LenovoIdeacentre 720-18apr Firmware< m25kt63a
LenovoV30a-22itl Firmware< o5akt33
LenovoV30a-24itl Firmware< o5akt33
LenovoV530s-07icb Firmware< m22kt49a
LenovoV530s-07icr Firmware< m1zkt40a
LenovoThinkstation P330 Tiny Firmware< m1ukt70a
LenovoThinkstation P360 Ultra Firmware< s0fkt27a
LenovoThinkstation P520 Firmware< s03kt58a
LenovoThinkstation P520c Firmware< s03kt58a

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-48188?
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
How severe is CVE-2022-48188?
CVE-2022-48188 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2022-48188?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-48188?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST