6.7
CVSSv3

CVE-2023-4029

Published: 17/08/2023 Updated: 24/08/2023
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 0

Vulnerability Summary

A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

Vulnerable Product Search on Vulmon Subscribe to Product

lenovo k14_type_21cu_firmware

lenovo k14_type_21cv_firmware

lenovo thinkpad_s2_yoga_gen_8_firmware

lenovo thinkpad_e14_gen_3_firmware

lenovo thinkpad_e15_gen_3_firmware

lenovo thinkpad_l13_gen_2_firmware

lenovo thinkpad_l13_gen_3_firmware

lenovo thinkpad_l13_gen_4_firmware

lenovo thinkpad_l13_yoga_gen_4_firmware

lenovo thinkpad_l13_yoga_gen_2_firmware

lenovo thinkpad_l13_yoga_gen_3_firmware

lenovo thinkpad_l14_gen_2_firmware

lenovo thinkpad_l14_gen_3_firmware

lenovo thinkpad_l14_gen_4_firmware

lenovo thinkpad_l15_gen_2_firmware

lenovo thinkpad_l15_gen_3_firmware

lenovo thinkpad_l15_gen_4_firmware

lenovo thinkpad_p14s_gen_2_firmware

lenovo thinkpad_t14_gen_2_firmware

lenovo thinkpad_t14s_gen_2_firmware

lenovo thinkpad_s2_gen_6_firmware

lenovo thinkpad_s2_gen_7_firmware

lenovo thinkpad_s2_gen_8_firmware

lenovo thinkpad_s2_yoga_gen_6_firmware

lenovo thinkpad_s2_yoga_gen_7_firmware

lenovo thinkpad_x13_gen_2_firmware