SB2025072860 - Lenovo update for Absolute Persistence BIOS module



SB2025072860 - Lenovo update for Absolute Persistence BIOS module

Published: July 28, 2025

Security Bulletin ID SB2025072860
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2024-6364)

The vulnerability allows an attacker to compromise the affected system.

The vulnerability exists due to an unspecified vulnerability in Absolute Persistence Software. An attacker with physical access to device and full hostile network control can execute arbitrary OS commands on the device. 


Remediation

Install update from vendor's website.