Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-1890: Lenovo Notebook BIOS Vulnerabilities - Lenovo Support US

A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

CVE
#vulnerability#ios#lenovo#bios#buffer_overflow

About Lenovo

  • Our Company
  • News
  • Investor Relations
  • Sustainability
  • Product Compliance
  • Product Security
  • Lenovo Open Source
  • Legal Information
  • Jobs at Lenovo

Shop

  • Laptops & Ultrabooks
  • Tablets
  • Desktops & All-in-Ones
  • Workstations
  • Accessories & Software
  • Servers
  • Storage
  • Networking
  • Laptop Deals
  • Outlet

Support

  • Drivers & Software
  • How To’s
  • Warranty Lookup
  • Parts Lookup
  • Contact Us
  • Repair Status Check
  • Imaging & Security Resources

Resources

  • Where to Buy
  • Shopping Help
  • Sales Order Status
  • Product Specifications (PSREF)
  • Forums
  • Registration
  • Product Accessibility
  • Environmental Information
  • Gaming Community
  • LenovoEDU Community
  • LenovoPRO Community

© Lenovo.
| | | |

Related news

New UEFI Firmware Flaws Reported in Several Lenovo Notebook Models

PC maker Lenovo has addressed yet another set of three shortcomings in the Unified Extensible Firmware Interface (UEFI) firmware affecting several Yoga, IdeaPad, and ThinkBook devices. "The vulnerabilities allow disabling UEFI Secure Boot or restoring factory default Secure Boot databases (incl. dbx): all simply from an OS," Slovak cybersecurity firm ESET explained in a series of tweets. UEFI

New UEFI Firmware Vulnerabilities Impact Several Lenovo Notebook Models

Consumer electronics maker Lenovo on Tuesday rolled out fixes to contain three security flaws in its UEFI firmware affecting over 70 product models. "The vulnerabilities can be exploited to achieve arbitrary code execution in the early phases of the platform boot, possibly allowing the attackers to hijack the OS execution flow and disable some important security features," Slovak cybersecurity

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907