ID

VAR-201611-0150


CVE

CVE-2016-8224


TITLE

Lenovo Notebook and ThinkServer Service disruption in the system (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2016-006116

DESCRIPTION

A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system. LenovoNotebook and ThinkServer are products of China Lenovo. The former is the notebook series, the latter is the server series. A local elevation of privilege vulnerability exists in the LenovoNotebook and ThinkServer systems. A local attacker can leverage this issue to gain elevated privileges. There are security vulnerabilities in Lenovo Notebook and ThinkServer systems

Trust: 2.52

sources: NVD: CVE-2016-8224 // JVNDB: JVNDB-2016-006116 // CNVD: CNVD-2016-11754 // BID: 94595 // VULHUB: VHN-97044

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-11754

AFFECTED PRODUCTS

vendor:lenovomodel:notebook yoga 900 13isk biosscope:eqversion: -

Trust: 1.6

vendor:lenovomodel:notebook yoga 710 11isk biosscope:eqversion: -

Trust: 1.6

vendor:lenovomodel:notebook yoga 710 11ikb biosscope:eqversion: -

Trust: 1.6

vendor:lenovomodel:notebook miix 710 12ikb biosscope:eqversion: -

Trust: 1.6

vendor:lenovomodel:notebook yoga 510 14isk biosscope:eqversion: -

Trust: 1.6

vendor:lenovomodel:notebook yoga 510 15isk biosscope:eqversion: -

Trust: 1.6

vendor:lenovomodel:notebook yoga 900s 12isk biosscope:eqversion: -

Trust: 1.6

vendor:lenovomodel:biosscope:eqversion: -

Trust: 1.6

vendor:lenovomodel:notebook xiaoxin air 12 biosscope:eqversion: -

Trust: 1.6

vendor:lenovomodel:notebook k41 80 biosscope:eqversion: -

Trust: 1.6

vendor:lenovomodel:notebook k21 80 biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkserver ts150 biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook g50 80 biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook ideapad 300 17isk biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook e40 80 biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook e31 80 biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook ideapad 300 14ibr biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook ideapad 300 14isk biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook ideapad 510s 12isk biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook 110 15ibr biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook ideapad 300 15isk biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook ideapad 300 15ibr biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkserver ts450 biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook e41 80 biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook e51 80 biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook b70 80 biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook 110 14ibr biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook g40 80 biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:notebook g50 80 touch biosscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkserverscope:eqversion:0

Trust: 0.9

vendor:lenovomodel:notebookscope:eqversion:0

Trust: 0.9

vendor:lenovomodel:110-14ibrscope: - version: -

Trust: 0.8

vendor:lenovomodel:110-14ibr biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:110-15ibrscope: - version: -

Trust: 0.8

vendor:lenovomodel:110-15ibr biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:b70-80scope: - version: -

Trust: 0.8

vendor:lenovomodel:b70-80 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:e31-80scope: - version: -

Trust: 0.8

vendor:lenovomodel:e31-80 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:e40-80scope: - version: -

Trust: 0.8

vendor:lenovomodel:e40-80 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:e41-80scope: - version: -

Trust: 0.8

vendor:lenovomodel:e41-80 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:e51-80scope: - version: -

Trust: 0.8

vendor:lenovomodel:e51-80 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:g40-80scope: - version: -

Trust: 0.8

vendor:lenovomodel:g40-80 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:g50-80scope: - version: -

Trust: 0.8

vendor:lenovomodel:g50-80 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:g50-80 touchscope: - version: -

Trust: 0.8

vendor:lenovomodel:g50-80 touch biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 300-14ibrscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 300-14ibr biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 300-14iskscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 300-14isk biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 300-15ibrscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 300-15ibr biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 300-15iskscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 300-15isk biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 300-17iskscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 300-17isk biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 510s-12iskscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideapad 510s-12isk biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:k21-80scope: - version: -

Trust: 0.8

vendor:lenovomodel:k21-80 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:k41-80scope: - version: -

Trust: 0.8

vendor:lenovomodel:k41-80 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:miix 710-12ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:miix 710-12ikb biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkserver ts150scope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkserver ts150 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkserver ts450scope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkserver ts450 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:xiaoxin air 12scope: - version: -

Trust: 0.8

vendor:lenovomodel:xiaoxin air 12 biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 510-14iskscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 510-14isk biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 510-15iskscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 510-15isk biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 710-11ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 710-11ikb biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 710-11iskscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 710-11isk biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 900-13iskscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 900-13isk biosscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 900s-12iskscope: - version: -

Trust: 0.8

vendor:lenovomodel:yoga 900s-12isk biosscope: - version: -

Trust: 0.8

sources: CNVD: CNVD-2016-11754 // BID: 94595 // JVNDB: JVNDB-2016-006116 // CNNVD: CNNVD-201611-644 // NVD: CVE-2016-8224

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-8224
value: MEDIUM

Trust: 1.0

NVD: CVE-2016-8224
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2016-11754
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201611-644
value: MEDIUM

Trust: 0.6

VULHUB: VHN-97044
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2016-8224
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:S/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2016-11754
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-97044
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:S/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-8224
baseSeverity: MEDIUM
baseScore: 4.4
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2016-11754 // VULHUB: VHN-97044 // JVNDB: JVNDB-2016-006116 // CNNVD: CNNVD-201611-644 // NVD: CVE-2016-8224

PROBLEMTYPE DATA

problemtype:CWE-310

Trust: 1.9

sources: VULHUB: VHN-97044 // JVNDB: JVNDB-2016-006116 // NVD: CVE-2016-8224

THREAT TYPE

local

Trust: 0.9

sources: BID: 94595 // CNNVD: CNNVD-201611-644

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-201611-644

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-006116

PATCH

title:LEN-9903url:https://support.lenovo.com/us/en/solutions/len_9903

Trust: 0.8

title:Patch for LenovoNotebook and ThinkServer Local Privilege Escalation Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/84823

Trust: 0.6

title:Lenovo Notebook and ThinkServer Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=65922

Trust: 0.6

sources: CNVD: CNVD-2016-11754 // JVNDB: JVNDB-2016-006116 // CNNVD: CNNVD-201611-644

EXTERNAL IDS

db:NVDid:CVE-2016-8224

Trust: 3.4

db:BIDid:94595

Trust: 2.0

db:JVNDBid:JVNDB-2016-006116

Trust: 0.8

db:CNNVDid:CNNVD-201611-644

Trust: 0.7

db:CNVDid:CNVD-2016-11754

Trust: 0.6

db:VULHUBid:VHN-97044

Trust: 0.1

sources: CNVD: CNVD-2016-11754 // VULHUB: VHN-97044 // BID: 94595 // JVNDB: JVNDB-2016-006116 // CNNVD: CNNVD-201611-644 // NVD: CVE-2016-8224

REFERENCES

url:https://support.lenovo.com/us/en/solutions/len_9903

Trust: 2.0

url:http://www.securityfocus.com/bid/94595

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-8224

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-8224

Trust: 0.8

url:https://support.lenovo.com/us/zh/solutions/len_9903

Trust: 0.6

url:http://www.lenovo.com/ca/en/

Trust: 0.3

sources: CNVD: CNVD-2016-11754 // VULHUB: VHN-97044 // BID: 94595 // JVNDB: JVNDB-2016-006116 // CNNVD: CNNVD-201611-644 // NVD: CVE-2016-8224

CREDITS

Alexander Ermolov from Digital Security ltd.

Trust: 0.3

sources: BID: 94595

SOURCES

db:CNVDid:CNVD-2016-11754
db:VULHUBid:VHN-97044
db:BIDid:94595
db:JVNDBid:JVNDB-2016-006116
db:CNNVDid:CNNVD-201611-644
db:NVDid:CVE-2016-8224

LAST UPDATE DATE

2024-08-14T15:44:33.904000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-11754date:2016-12-02T00:00:00
db:VULHUBid:VHN-97044date:2016-12-06T00:00:00
db:BIDid:94595date:2016-12-20T02:04:00
db:JVNDBid:JVNDB-2016-006116date:2016-12-07T00:00:00
db:CNNVDid:CNNVD-201611-644date:2016-11-30T00:00:00
db:NVDid:CVE-2016-8224date:2016-12-06T19:15:27.513

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-11754date:2016-12-02T00:00:00
db:VULHUBid:VHN-97044date:2016-11-29T00:00:00
db:BIDid:94595date:2016-11-30T00:00:00
db:JVNDBid:JVNDB-2016-006116date:2016-12-07T00:00:00
db:CNNVDid:CNNVD-201611-644date:2016-11-30T00:00:00
db:NVDid:CVE-2016-8224date:2016-11-29T20:59:02.437