cbcvebase.
CVE-2022-1892
published 2023-01-26

CVE-2022-1892: A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.4th percentile
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

Affected

71 ranges· showing 25
VendorProductVersion rangeFixed in
lenovo100e_2nd_gen_firmware< frcn23wwfrcn23ww
lenovo100w_gen_3_firmware< gacn38wwgacn38ww
lenovo13w_yoga_firmware< jacn31wwjacn31ww
lenovo14w_gen_2_firmware< h0cn21wwh0cn21ww
lenovo300e_2nd_gen_firmware< frcn23wwfrcn23ww
lenovo300w_gen_3_firmware< gacn38wwgacn38ww
lenovo500w_gen_3_firmware< g6cn40wwg6cn40ww
lenovo730s-13iml_firmware< brcn20wwbrcn20ww
lenovobios
lenovoflex_3-11ada05_firmware< fpcn26wwfpcn26ww
lenovoflex_5-14alc05_firmware< gjcn27wwgjcn27ww
lenovoflex_5-14are05_firmware< eecn39wweecn39ww
lenovoflex_5-14iil05_firmware< eecn40wweecn40ww
lenovoflex_5-14itl05_firmware< fxcn38wwfxcn38ww
lenovoflex_5-15alc05_firmware< gjcn27wwgjcn27ww
lenovoflex_5-15iil05_firmware< eccn40wweccn40ww
lenovoflex_5-15itl05_firmware< fxcn38wwfxcn38ww
lenovoideapad_1-11ada05_firmware< fqcn26wwfqcn26ww
lenovoideapad_1-11igl05_firmware< dwcn24wwdwcn24ww
lenovoideapad_1-14ada05_firmware< fqcn26wwfqcn26ww
lenovoideapad_1-14igl05_firmware< dwcn24wwdwcn24ww
lenovoideapad_3-14ada05_firmware< e8cn36wwe8cn36ww
lenovoideapad_3-14ada6_firmware< hbcn24wwhbcn24ww
lenovoideapad_3-14alc6_firmware< glcn48wwglcn48ww
lenovoideapad_3-15ada05_firmware< e8cn36wwe8cn36ww
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.