ID

VAR-201608-0492


TITLE

Lenovo ThinkPad BIOS System Management Mode Arbitrary Code Execution Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-05721

DESCRIPTION

BIOS (BasicInput/OutputSystem) is the basic output input system, which is the most basic software code loaded on the computer hardware system. There is a security vulnerability in LenovoThinkPadBIOS. In the system management mode, an attacker with local administrative access can use the vulnerability to execute arbitrary code, disable flash write protection, infect platform firmware, disable secure boot, bypass virtual security mode, and so on. Lenovo ThinkPad is prone to a local privilege escalation vulnerability

Trust: 0.81

sources: CNVD: CNVD-2016-05721 // BID: 91538

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-05721

AFFECTED PRODUCTS

vendor:lenovomodel:thinkpad yoga 11escope:eqversion:0

Trust: 0.9

vendor:lenovomodel:thinkpadscope: - version: -

Trust: 0.6

vendor:lenovomodel:thinkpad carbonscope:eqversion:x10

Trust: 0.6

vendor:lenovomodel:thinkpad tabletscope:eqversion:80

Trust: 0.6

vendor:lenovomodel:thinkpad tabletscope:eqversion:100

Trust: 0.6

vendor:lenovomodel:thinkstation d30 (typescope:eqversion:4353-4354)0

Trust: 0.3

vendor:lenovomodel:thinkstation d30 (typescope:eqversion:4223-4228-4229)0

Trust: 0.3

vendor:lenovomodel:thinkstation c30 (typescope:eqversion:1136-1137)0

Trust: 0.3

vendor:lenovomodel:thinkstation c30 (typescope:eqversion:1095-1096-1097)0

Trust: 0.3

vendor:lenovomodel:thinkpad yogascope:eqversion:150

Trust: 0.3

vendor:lenovomodel:thinkpadscope:eqversion:x2500

Trust: 0.3

vendor:lenovomodel:thinkpad x240sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpadscope:eqversion:x2400

Trust: 0.3

vendor:lenovomodel:thinkpad x230sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad x230i tabletscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad x230iscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad tabletscope:eqversion:x2300

Trust: 0.3

vendor:lenovomodel:thinkpadscope:eqversion:x2300

Trust: 0.3

vendor:lenovomodel:thinkpad x140escope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad x131escope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad w550sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad w541scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad w540scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad w530scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad ultrazoomscope:eqversion:1

Trust: 0.3

vendor:lenovomodel:thinkpad ultranav wizardscope:eqversion:3

Trust: 0.3

vendor:lenovomodel:thinkpad twist/edge s230scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t550scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t540pscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t530iscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t530scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t450sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t450scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t440sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t440pscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t440scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t431sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t430siscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t430sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t430iscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t430scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t430scope:eqversion: -

Trust: 0.3

vendor:lenovomodel:thinkpad t420scope:eqversion: -

Trust: 0.3

vendor:lenovomodel:thinkpad t400scope:eqversion: -

Trust: 0.3

vendor:lenovomodel:thinkpad s540scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad s531scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad s430scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad s3-s440scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad s3 yogascope:eqversion:140

Trust: 0.3

vendor:lenovomodel:thinkpad l540scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad l450scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad l440scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad l430scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad helixscope:eqversion:(3xxx)0

Trust: 0.3

vendor:lenovomodel:thinkpad helixscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad edge s430scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad edge e555scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad edge e455scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad e565scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad e465scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad 11escope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpadscope:eqversion:100

Trust: 0.3

vendor:lenovomodel:thinkpadscope:eqversion:x61

Trust: 0.3

vendor:lenovomodel:thinkpadscope:eqversion:x220

Trust: 0.3

vendor:lenovomodel:thinkpadscope:eqversion:x201

Trust: 0.3

vendor:lenovomodel:thinkpad t61scope: - version: -

Trust: 0.3

vendor:lenovomodel:thinkpad t60scope: - version: -

Trust: 0.3

vendor:lenovomodel:thinkpad t530scope: - version: -

Trust: 0.3

vendor:lenovomodel:thinkpad t430scope: - version: -

Trust: 0.3

vendor:lenovomodel:thinkpad t43scope: - version: -

Trust: 0.3

vendor:lenovomodel:thinkpad t410scope: - version: -

Trust: 0.3

vendor:lenovomodel:system m5scope:eqversion:x36500

Trust: 0.3

vendor:lenovomodel:system m5scope:eqversion:x35500

Trust: 0.3

vendor:lenovomodel:system m5scope:eqversion:x35000

Trust: 0.3

vendor:lenovomodel:ideapad z50-75scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad yogascope:eqversion:3140

Trust: 0.3

vendor:lenovomodel:ideapad s41-75scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad s41-35scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad m41-70scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad k41-70scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad g70-35scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad g51-35scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad g50-70mscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad g41-35scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad g40-75mscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad flexscope:eqversion:3-15700

Trust: 0.3

vendor:lenovomodel:ideapad flexscope:eqversion:3-14700

Trust: 0.3

vendor:lenovomodel:ideapad flex 3-1435scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:ideapad 305-15ihwscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:flex systemscope:eqversion:x880x60

Trust: 0.3

vendor:lenovomodel:flex systemscope:eqversion:x8800

Trust: 0.3

vendor:lenovomodel:flex systemscope:eqversion:x480x60

Trust: 0.3

vendor:lenovomodel:flex systemscope:eqversion:x280x60

Trust: 0.3

vendor:lenovomodel:flex system m5scope:eqversion:x2400

Trust: 0.3

sources: CNVD: CNVD-2016-05721 // BID: 91538

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-05721
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2016-05721
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-05721

THREAT TYPE

local

Trust: 0.3

sources: BID: 91538

TYPE

Unknown

Trust: 0.3

sources: BID: 91538

EXTERNAL IDS

db:LENOVOid:LEN-8324

Trust: 0.9

db:CNVDid:CNVD-2016-05721

Trust: 0.6

db:BIDid:91538

Trust: 0.3

sources: CNVD: CNVD-2016-05721 // BID: 91538

REFERENCES

url:https://support.lenovo.com/us/zh/solutions/len-8324

Trust: 0.6

url:http://www.lenovo.com/ca/en/

Trust: 0.3

url:https://github.com/cr4sh/thinkpwn

Trust: 0.3

url:http://blog.cr4.sh/2016/06/exploring-and-exploiting-lenovo.html

Trust: 0.3

url:https://support.lenovo.com/us/en/solutions/len-8324

Trust: 0.3

sources: CNVD: CNVD-2016-05721 // BID: 91538

CREDITS

Dmytro Oleksiuk

Trust: 0.3

sources: BID: 91538

SOURCES

db:CNVDid:CNVD-2016-05721
db:BIDid:91538

LAST UPDATE DATE

2022-05-17T02:02:27.013000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-05721date:2016-08-01T00:00:00
db:BIDid:91538date:2016-07-14T20:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-05721date:2016-08-01T00:00:00
db:BIDid:91538date:2016-06-30T00:00:00