A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Project Subscriptions

Vendors Products
D330-10igl Subscribe
D330-10igl Firmware Subscribe
Ideapad 5 Pro 16arh7 Subscribe
Ideapad 5 Pro 16arh7 Firmware Subscribe
Ideapad 5 Pro 16iah7 Subscribe
Ideapad 5 Pro 16iah7 Firmware Subscribe
Ideapad Duet 3 10igl5 Subscribe
Ideapad Duet 3 10igl5 Firmware Subscribe
Ideapad Slim 7-14iil05 Subscribe
Ideapad Slim 7-14iil05 Firmware Subscribe
Ideapad Slim 7-14itl05 Subscribe
Ideapad Slim 7-14itl05 Firmware Subscribe
Ideapad Slim 7-15iil05 Subscribe
Ideapad Slim 7-15iil05 Firmware Subscribe
Slim 7-14are05 Subscribe
Slim 7-14are05 Firmware Subscribe
Slim 7-15imh05 Subscribe
Slim 7-15imh05 Firmware Subscribe
Slim 7-15itl05 Subscribe
Slim 7-15itl05 Firmware Subscribe
Slim 7 16arh7 Subscribe
Slim 7 16arh7 Firmware Subscribe
Thinkbook 13x Itg Subscribe
Thinkbook 13x Itg Firmware Subscribe
Thinkbook 14 G2 Are Subscribe
Thinkbook 14 G2 Are Firmware Subscribe
Thinkbook 14 G2 Itl Subscribe
Thinkbook 14 G2 Itl Firmware Subscribe
Thinkbook 14 G3 Acl Subscribe
Thinkbook 14 G3 Acl Firmware Subscribe
Thinkbook 14 G3 Itl Subscribe
Thinkbook 14 G3 Itl Firmware Subscribe
Thinkbook 14 G4\+ Ara Subscribe
Thinkbook 14 G4\+ Ara Firmware Subscribe
Thinkbook 14 G4\+ Iap Subscribe
Thinkbook 14 G4\+ Iap Firmware Subscribe
Thinkbook 14p G3 Arh Subscribe
Thinkbook 14p G3 Arh Firmware Subscribe
Thinkbook 14s Yoga Itl Subscribe
Thinkbook 14s Yoga Itl Firmware Subscribe
Thinkbook 15 G2 Are Subscribe
Thinkbook 15 G2 Are Firmware Subscribe
Thinkbook 15 G2 Itl Subscribe
Thinkbook 15 G2 Itl Firmware Subscribe
Thinkbook 15 G3 Acl Subscribe
Thinkbook 15 G3 Acl Firmware Subscribe
Thinkbook 15 G3 Itl Subscribe
Thinkbook 15 G3 Itl Firmware Subscribe
Thinkbook 15 G4 Aba Subscribe
Thinkbook 15 Gd Aba Firmware Subscribe
Thinkbook 15p G2 Ith Subscribe
Thinkbook 15p G2 Ith Firmware Subscribe
Thinkbook 15p Imp Subscribe
Thinkbook 15p Imp Firmware Subscribe
Thinkbook 16 G4\+ Ara Subscribe
Thinkbook 16 G4\+ Ara Firmware Subscribe
Thinkbook 16 G4\+ Iap Subscribe
Thinkbook 16 G4\+ Iap Firmware Subscribe
Thinkbook 16p G3 Arh Subscribe
Thinkbook 16p G3 Arh Firmware Subscribe
Thinkbook 16p Nx Arh Subscribe
Thinkbook 16p Nx Arh Firmware Subscribe
Thinkbook Plus G2 Itg Subscribe
Thinkbook Plus G2 Itg Firmware Subscribe
Thinkbook Plus G3 Iap Subscribe
Thinkbook Plus G3 Iap Firmware Subscribe
Yoga Creator 7-15imh05 Subscribe
Yoga Creator 7-15imh05 Firmware Subscribe
Yoga Duet 7-13iml05 Subscribe
Yoga Duet 7-13iml05 Firmware Subscribe
Yoga Duet 7-13itl6 Subscribe
Yoga Duet 7-13itl6-lte Subscribe
Yoga Duet 7-13itl6-lte Firmware Subscribe
Yoga Duet 7-13itl6 Firmware Subscribe
Yoga Slim 7-14are05 Subscribe
Yoga Slim 7-14are05 Firmware Subscribe
Yoga Slim 7-14iil05 Subscribe
Yoga Slim 7-14iil05 Firmware Subscribe
Yoga Slim 7-14itl05 Subscribe
Yoga Slim 7-14itl05 Firmware Subscribe
Yoga Slim 7-15iil05 Subscribe
Yoga Slim 7-15iil05 Firmware Subscribe
Yoga Slim 7-15imh05 Subscribe
Yoga Slim 7-15imh05 Firmware Subscribe
Yoga Slim 7-15itl05 Subscribe
Yoga Slim 7-15itl05 Firmware Subscribe
Yoga Slim 7 Pro 16arh7 Subscribe
Yoga Slim 7 Pro 16arh7 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-42806 A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the product Impact section of LEN-94952


Workaround

No workaround given by the vendor.

History

Wed, 02 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-04-02T15:01:31.058Z

Reserved: 2022-10-07T19:58:27.731Z

Link: CVE-2022-3430

cve-icon Vulnrichment

Updated: 2024-08-03T01:07:06.525Z

cve-icon NVD

Status : Modified

Published: 2023-01-23T17:15:10.647

Modified: 2024-11-21T07:19:29.873

Link: CVE-2022-3430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses