CVE-2023-34419
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
Affected (30)
Products: Lenovo: Legion 5 Pro 16iah7h Firmware, Legion 5 Pro 16iah7 Firmware, Legion 5 Pro 16arh7 Firmware, Legion 5 Pro 16arh7h Firmware, Legion 5 15arh7 Firmware, Legion 5 15arh7h Firmware, Legion 5 15iah7h Firmware, Legion 5 15iah7 Firmware, Legion 5 Pro 16ach6 Firmware, Legion 5 Pro 16ach6h Firmware, Legion 5 Pro 16ith6 Firmware, Legion 5 Pro 16ith6h Firmware, Legion 5 15ach6 Firmware, Legion 5 15ach6a Firmware, Legion 5 15ach6h Firmware, Legion 5 15ith6 Firmware, Legion 5 15ith6h Firmware, Legion 5 17ach6 Firmware, Legion 5 17ach6h Firmware, Legion 5 17ith6 Firmware, Legion 5 17ith6h Firmware, Legion 7 16arha7 Firmware, Legion 7 16achg6 Firmware, Legion 7 16ithg6 Firmware, Legion Pro 5 16irx8 Firmware, Legion Pro 7 16irx8 Firmware, Legion Pro 7 16irx8h Firmware, Legion S7 16arha7 Firmware, Thinkbook 16p G3 Arh Firmware, Thinkbook 15p G2 Ith Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before j2cn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16iah7h | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before j2cn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16iah7 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16arh7 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16arh7h | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15arh7 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15arh7h | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before j2cn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15iah7h | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before j2cn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15iah7 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16ach6 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16ach6h | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16ith6 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16ith6h | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ach6 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ach6a | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ach6h | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ith6 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ith6h | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17ach6 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17ach6h | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17ith6 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17ith6h | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 7 16arha7 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 7 16achg6 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 7 16ithg6 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before kwcn37ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Pro 5 16irx8 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before kwcn37ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Pro 7 16irx8 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before kwcn37ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Pro 7 16irx8h | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion S7 16arha7 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkbook 16p G3 Arh | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkbook 15p G2 Ith | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.