cbcvebase.
CVE-2017-3753
published 2017-08-10

CVE-2017-3753: A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability…

medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.

Affected

86 ranges· showing 25
VendorProductVersion rangeFixed in
lenovo63_firmware
lenovoh50-30g_firmware
lenovoideacentre_510s-23isu_firmware
lenovom4500_firmware
lenovom4500_id_firmware
lenovom4550_id_firmware
lenovos200z_firmware
lenovos500_firmware
lenovothinkcentre_e73_firmware
lenovothinkcentre_e73s_firmware
lenovothinkcentre_e73z_firmware
lenovothinkcentre_e74_firmware
lenovothinkcentre_e74s_firmware
lenovothinkcentre_e74z_firmware
lenovothinkcentre_e79_firmware
lenovothinkcentre_e93_firmware
lenovothinkcentre_e93z_firmware
lenovothinkcentre_edge_62z_firmware
lenovothinkcentre_m4500k_firmware
lenovothinkcentre_m4500q_firmware
lenovothinkcentre_m4500t_s_firmware
lenovothinkcentre_m4600t_s_firmware
lenovothinkcentre_m600_firmware
lenovothinkcentre_m6500t_s_firmware
lenovothinkcentre_m6600_firmware

CVSS provenance

nvdv3.06.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH