PT-2022-3639 · Lenovo · Readybootdxe+1

CVE-2022-1892

·

Published

2022-07-12

·

Updated

2023-02-03

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lenovo Notebook products (affected versions not specified)
Description A buffer overflow issue in the SystemBootManagerDxe driver may allow an attacker with local privileges to execute arbitrary code. This issue is related to the ReadyBootDxe driver in Lenovo Notebook products' firmware, which can be exploited to achieve the same result.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04424
CVE-2022-1892

Affected Products

Readybootdxe
Systembootmanagerdxe