A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
References
Link | Resource |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-91369 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Information
Published : 2023-01-26 13:15
Updated : 2023-02-03 10:03
NVD link : CVE-2022-1891
Mitre link : CVE-2022-1891
JSON object : View
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Products Affected
lenovo
- yoga_c640-13iml
- thinkbook_14-iil
- thinkbook_14-iml_firmware
- thinkbook_14-iil_firmware
- thinkbook_15-iml_firmware
- yoga_c640-13iml_lte
- thinkbook_15-iil
- yoga_c640-13iml_firmware
- thinkbook_14-iml
- thinkbook_15-iml
- thinkbook_15-iil_firmware
- yoga_c640-13iml_lte_firmware