CVE-2017-3753
published 2017-08-10CVE-2017-3753: A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability…
PriorityP429medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
EPSS
0.52%
40.5th percentile
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | 63_firmware | — | — |
| lenovo | h50-30g_firmware | — | — |
| lenovo | ideacentre_510s-23isu_firmware | — | — |
| lenovo | m4500_firmware | — | — |
| lenovo | m4500_id_firmware | — | — |
| lenovo | m4550_id_firmware | — | — |
| lenovo | s200z_firmware | — | — |
| lenovo | s500_firmware | — | — |
| lenovo | thinkcentre_e73_firmware | — | — |
| lenovo | thinkcentre_e73s_firmware | — | — |
| lenovo | thinkcentre_e73z_firmware | — | — |
| lenovo | thinkcentre_e74_firmware | — | — |
| lenovo | thinkcentre_e74s_firmware | — | — |
| lenovo | thinkcentre_e74z_firmware | — | — |
| lenovo | thinkcentre_e79_firmware | — | — |
| lenovo | thinkcentre_e93_firmware | — | — |
| lenovo | thinkcentre_e93z_firmware | — | — |
| lenovo | thinkcentre_edge_62z_firmware | — | — |
| lenovo | thinkcentre_m4500k_firmware | — | — |
| lenovo | thinkcentre_m4500q_firmware | — | — |
| lenovo | thinkcentre_m4500t_s_firmware | — | — |
| lenovo | thinkcentre_m4600t_s_firmware | — | — |
| lenovo | thinkcentre_m600_firmware | — | — |
| lenovo | thinkcentre_m6500t_s_firmware | — | — |
| lenovo | thinkcentre_m6600_firmware | — | — |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-97c7-jg3h-5vf5: A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc
ghsa_unreviewed·2022-05-17
CVE-2017-3753 [HIGH] CWE-94 GHSA-97c7-jg3h-5vf5: A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-08-24·CVSS 7.8
CVE-2017-13168 linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3753-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
privileges. (CVE-2017-13168)
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-08-10
Published