Lenovo issues emergency security patch for hundreds of models

Lenovo Legion Slim 7i
(Image credit: Future)

Lenovo has fixed a number of major BIOS flaws which allow threat actors to potentially launch all kinds of devastating cyberattacks across a wide range of its products, from desktop PCs, to laptops.

In a security advisory published earlier this week, the company said that hundreds of its devices, from Desktop, All in One, IdeaCentre, Legion, ThinkCentre, ThinkPad, ThinkAgile, ThinkStation, and ThinkSystem series’, were vulnerable to a total of six different vulnerabilities. 

These flaws could be abused by threat actors to steal sensitive data, escalate privileges, launch denial of service attacks and, in extreme cases, allow for arbitrary code execution.

Leaking data, risking arbitrary code execution

The flaws Lenovo fixed include CVE-2021-28216 (pointer flaw in TianoCore EDK II BIOS - allows for elevation of privilege and arbitrary code execution), CVE-2022-40134 (information leak flaw in the SMI Set Bios Password SMI Handler - allows for SMM memory reading), CVE-2022-40135 (information leak vulnerability in the Smart USB Protection SMI Handler, allows for SMM memory reading), CVE-2022-40136 (information leak flaw in SMI Handler used for configuring platform settings over WMI, allows for SMM memory reading), CVE-2022-40137 (buffer overflow in the WMI SMI Handler, allows for arbitrary code execution), American Megatrends security enhancements (no CVEs).

The fix for these flaws comes as part of the latest BIOS update for the abovementioned devices, with the company advising all system admins to apply them immediately. 

More patches are expected to be released before the end of this month, as well as in October, with a short list of models getting their updates early next year. 

Those interested in fixing their endpoints should navigate to Lenovo’s “Drivers & Software” portal, search for their devices by name, and choose “Manual Update”. That will download the latest BIOS firmware version, which they can then manually install.

You can find the full list of the affected devices on this link

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
MediaTek
MediaTek reveals host of security vulnerabilities, so patch now
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
New UEFI Secure Boot flaw exposes systems to bootkits
AMD Ryzen 5 7600X processor
AMD confirms processor security flaws after Asus patch slips out early
AMD logo
AMD patches high severity security flaw affecting Zen chips
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
Security
Broadcom releases fixes for multiple VMware security flaws
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)