A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Project Subscriptions

Vendors Products
Thinkcentre E93 Subscribe
Thinkcentre E93 Firmware Subscribe
Thinkcentre M4500q Subscribe
Thinkcentre M4500q Firmware Subscribe
Thinkcentre M600 Subscribe
Thinkcentre M600 Firmware Subscribe
Thinkcentre M6500t\/s Subscribe
Thinkcentre M6500t\/s Firmware Subscribe
Thinkcentre M700 Tiny Subscribe
Thinkcentre M700 Tiny Firmware Subscribe
Thinkcentre M73 Subscribe
Thinkcentre M73 Firmware Subscribe
Thinkcentre M73p Subscribe
Thinkcentre M73p Firmware Subscribe
Thinkcentre M800 Subscribe
Thinkcentre M800 Firmware Subscribe
Thinkcentre M818z Subscribe
Thinkcentre M818z Firmware Subscribe
Thinkcentre M83 Subscribe
Thinkcentre M83 Firmware Subscribe
Thinkcentre M8500t\/s Subscribe
Thinkcentre M8500t\/s Firmware Subscribe
Thinkcentre M900 Subscribe
Thinkcentre M900 Firmware Subscribe
Thinkcentre M900x Subscribe
Thinkcentre M900x Firmware Subscribe
Thinkcentre M93 Subscribe
Thinkcentre M93 Firmware Subscribe
Thinkcentre M93p Subscribe
Thinkcentre M93p Firmware Subscribe
Thinkcentre X1 Subscribe
Thinkcentre X1 Firmware Subscribe
Thinkstation P300 Subscribe
Thinkstation P300 Firmware Subscribe
Thinkstation P500 Subscribe
Thinkstation P500 Firmware Subscribe
Thinkstation P700 Subscribe
Thinkstation P700 Firmware Subscribe
Thinkstation P900 Subscribe
Thinkstation P900 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-26999 A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-67440.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:01:07.776Z

Reserved: 2021-08-18T00:00:00

Link: CVE-2021-3719

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-12T22:15:07.957

Modified: 2024-11-21T06:22:14.657

Link: CVE-2021-3719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses