SB2022041803 - Security restrictions bypass in multiple Lenovo products



SB2022041803 - Security restrictions bypass in multiple Lenovo products

Published: April 18, 2022

Security Bulletin ID SB2022041803
Severity
Low
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2021-3971)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an error in driver used during older manufacturing processes and was mistakenly included in the BIOS image. A local privileged user can modify firmware protection region by changing an NVRAM variable and bypass implemented security restrictions.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.