A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.
References
Link | Resource |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-67440 | Vendor Advisory |
https://support.lenovo.com/us/en/product_security/LEN-67440 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
Configuration 17 (hide)
AND |
|
Configuration 18 (hide)
AND |
|
Configuration 19 (hide)
AND |
|
Configuration 20 (hide)
AND |
|
History
21 Nov 2024, 06:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.lenovo.com/us/en/product_security/LEN-67440 - Vendor Advisory |
19 Nov 2021, 21:57
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 7.2
v3 : 6.7 |
CPE | cpe:2.3:h:lenovo:thinkstation_p300:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m93p_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m900x:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m93p:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m73p_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m83:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m73_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m818z:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkstation_p900_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m700_tiny:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m700_tiny_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m93:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m8500t\/s_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m73:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_x1:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m800:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m900:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m900x_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m6500t\/s:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_e93_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_e93:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m83_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m73p:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m4500q:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkstation_p700:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m93_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkstation_p300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m4500q_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m8500t\/s:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkstation_p900:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkstation_p500:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_x1_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m6500t\/s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkstation_p700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m900_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m818z_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkcentre_m600_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkcentre_m600:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkstation_p500_firmware:*:*:*:*:*:*:*:* |
|
CWE | NVD-CWE-noinfo | |
References | (CONFIRM) https://support.lenovo.com/us/en/product_security/LEN-67440 - Vendor Advisory |
12 Nov 2021, 22:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-11-12 22:15
Updated : 2024-11-21 06:22
NVD link : CVE-2021-3719
Mitre link : CVE-2021-3719
CVE.ORG link : CVE-2021-3719
JSON object : View
Products Affected
lenovo
- thinkcentre_m600_firmware
- thinkcentre_m73_firmware
- thinkcentre_m93p_firmware
- thinkcentre_m900_firmware
- thinkcentre_m6500t\/s_firmware
- thinkstation_p300
- thinkcentre_m818z
- thinkstation_p900
- thinkcentre_e93
- thinkcentre_e93_firmware
- thinkcentre_m900
- thinkcentre_m6500t\/s
- thinkcentre_m93_firmware
- thinkstation_p500
- thinkstation_p900_firmware
- thinkcentre_m93
- thinkstation_p500_firmware
- thinkcentre_m800_firmware
- thinkcentre_m83_firmware
- thinkcentre_m73p_firmware
- thinkcentre_m900x
- thinkstation_p700
- thinkcentre_m700_tiny
- thinkcentre_m93p
- thinkcentre_x1_firmware
- thinkcentre_m700_tiny_firmware
- thinkcentre_m73p
- thinkcentre_m8500t\/s
- thinkcentre_m800
- thinkcentre_m83
- thinkcentre_m8500t\/s_firmware
- thinkcentre_m600
- thinkstation_p700_firmware
- thinkcentre_x1
- thinkcentre_m900x_firmware
- thinkstation_p300_firmware
- thinkcentre_m73
- thinkcentre_m4500q
- thinkcentre_m818z_firmware
- thinkcentre_m4500q_firmware
CWE