CVE-2022-1892
published 2023-01-26CVE-2022-1892: A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.4th percentile
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Affected
71 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | 100e_2nd_gen_firmware | < frcn23ww | frcn23ww |
| lenovo | 100w_gen_3_firmware | < gacn38ww | gacn38ww |
| lenovo | 13w_yoga_firmware | < jacn31ww | jacn31ww |
| lenovo | 14w_gen_2_firmware | < h0cn21ww | h0cn21ww |
| lenovo | 300e_2nd_gen_firmware | < frcn23ww | frcn23ww |
| lenovo | 300w_gen_3_firmware | < gacn38ww | gacn38ww |
| lenovo | 500w_gen_3_firmware | < g6cn40ww | g6cn40ww |
| lenovo | 730s-13iml_firmware | < brcn20ww | brcn20ww |
| lenovo | bios | — | — |
| lenovo | flex_3-11ada05_firmware | < fpcn26ww | fpcn26ww |
| lenovo | flex_5-14alc05_firmware | < gjcn27ww | gjcn27ww |
| lenovo | flex_5-14are05_firmware | < eecn39ww | eecn39ww |
| lenovo | flex_5-14iil05_firmware | < eecn40ww | eecn40ww |
| lenovo | flex_5-14itl05_firmware | < fxcn38ww | fxcn38ww |
| lenovo | flex_5-15alc05_firmware | < gjcn27ww | gjcn27ww |
| lenovo | flex_5-15iil05_firmware | < eccn40ww | eccn40ww |
| lenovo | flex_5-15itl05_firmware | < fxcn38ww | fxcn38ww |
| lenovo | ideapad_1-11ada05_firmware | < fqcn26ww | fqcn26ww |
| lenovo | ideapad_1-11igl05_firmware | < dwcn24ww | dwcn24ww |
| lenovo | ideapad_1-14ada05_firmware | < fqcn26ww | fqcn26ww |
| lenovo | ideapad_1-14igl05_firmware | < dwcn24ww | dwcn24ww |
| lenovo | ideapad_3-14ada05_firmware | < e8cn36ww | e8cn36ww |
| lenovo | ideapad_3-14ada6_firmware | < hbcn24ww | hbcn24ww |
| lenovo | ideapad_3-14alc6_firmware | < glcn48ww | glcn48ww |
| lenovo | ideapad_3-15ada05_firmware | < e8cn36ww | e8cn36ww |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-26
Published