
CVE-2024-3100
https://notcve.org/view.php?id=CVE-2024-3100
13 Sep 2024 — A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code. • https://support.lenovo.com/us/en/product_security/LEN-165524 • CWE-121: Stack-based Buffer Overflow •

CVE-2022-3431
https://notcve.org/view.php?id=CVE-2022-3431
09 Oct 2023 — A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. Una vulnerabilidad potencial en un driver utilizado durante el proceso de fabricación de algunos dispositivos de consumo Lenovo Notebook que no se desactivó por error, puede permitir que un atacante con privilegios elevados modifique la configuración de ... • https://support.lenovo.com/us/en/product_security/LEN-94952 • CWE-276: Incorrect Default Permissions •

CVE-2023-4028
https://notcve.org/view.php?id=CVE-2023-4028
17 Aug 2023 — A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. Se ha identificado un desbordamiento de búfer en el controlador SystemUserMasterHddPwdDxe de algunos productos portátiles de Lenovo que puede permitir a un atacante con acceso local y privilegios elevados ejecutar código arbitrario. • https://support.lenovo.com/us/en/product_security/LEN-134879 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2022-3430
https://notcve.org/view.php?id=CVE-2022-3430
23 Jan 2023 — A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. Una vulnerabilidad potencial en el controlador de configuración WMI en algunos dispositivos portátiles Lenovo Notebook puede permitir que un atacante con privilegios elevados modifique la configuración de arranque seguro modificando una variable NVRAM. • https://support.lenovo.com/us/en/product_security/LEN-94952 • CWE-276: Incorrect Default Permissions •