Lenovo BIOS Vulnerabilities (July 2021)
Lenovo BIOS Vulnerabilities (July 2021)
Lenovo BIOS Vulnerabilities (July 2021)
Lenovo Security Advisory: LEN-65529
Potential Impact: Privilege escalation
Severity: Medium
Scope of Impact: Lenovo-specific
CVE Identifier: CVE-2021-3452, CVE-2021-3453, CVE-2021-3614
Summary Description:
The following vulnerabilities were reported in Lenovo BIOS:
CVE-2021-3452: A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
CVE-2021-3453: Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
CVE-2021-3614: A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage.
Mitigation Strategy for Customers (what you should do to protect yourself):
Update system firmware to the version (or newer) indicated for your model in the Product Impact section.
To download the version specified for your product below, follow these steps:
Navigate to the Drivers & Software support site for your product:
- Lenovo Products (sold worldwide, except in China): https://support.lenovo.com/
- Lenovo Products (sold in China): https://newsupport.lenovo.com.cn/
- IBM-branded System x Legacy Products: https://www.ibm.com/support/fixcentral/
- Search for your product by name or machine type.
- Click Drivers & Software on the left menu panel.
- Click on Manual Update to browse by Component type.
- Compare the minimum fix version for your product from the applicable product table below with the latest version posted on the support site.
Lenovo also offers tools to assist with update management as an alternative to the manual steps described above. Refer to the following for additional help:
PC Products and Software: https://support.lenovo.com/us/en/solutions/ht504759
Server and Enterprise Software: https://support.lenovo.com/us/en/solutions/lnvo-lxcaupd and https://datacentersupport.lenovo.com/us/en/documents/lnvo-center
Click below links to view affected products:
Acknowledgement:
CVE-2021-3452, CVE-2021-3453: Lenovo thanks Binarly efiXplorer team for reporting these issues.
CVE-2021-3614: Lenovo thanks Tim Boyd, NCC Group for reporting this issue.
Revision History:
Revision | Date | Description |
---|---|---|
3 | 2021-11-15 | Updated Desktop and Lenovo Notebook |
2 | 2021-08-06 | Updated Lenovo Notebook, ThinkPad |
1 | 2021-07-13 | Initial release |
For a complete list of all Lenovo Product Security Advisories, click here.
For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.
Product Impact:
Product | Component | CVE-2021-3453 |
ideacentre AIO 5-24IMB05 Desktop | BIOS for Windows 10 (64-bit) - ideacentre AIO 5-24IMB05 Desktop | O4UKT32A |
ideacentre AIO 5-27IMB05 Desktop | BIOS for Windows 10 (64-bit) - ideacentre AIO 5-27IMB05 Desktop | O4VKT33A |
Product | Component | CVE-2021-3614 |
100e 2nd Gen Notebook (Lenovo) (Type 82GJ) | BIOS Update for Windows 10 (64-bit) - Lenovo 100e 2nd Gen (MT:82GJ), Lenovo 300e 2nd Gen (MT:82GK) | FRCN20WW |
300e 2nd Gen Notebook (Lenovo) (Type 82GK) | BIOS Update for Windows 10 (64-bit) - Lenovo 100e 2nd Gen (MT:82GJ), Lenovo 300e 2nd Gen (MT:82GK) | FRCN20WW |
730S-13IML Laptop (ideapad) | BIOS Update for Windows 10 (64-bit) - Yoga S730-13IML,ideapad 730S-13IML | BRCN18WW |
Flex 5-14ALC05 Laptop (ideapad) | BIOS Update for Windows 10 (64-bit) - Flex 5 14ALC05, Flex 5 15ALC05 | GJCN22WW |
Flex 5-15ALC05 Laptop (ideapad) | BIOS Update for Windows 10 (64-bit) - Flex 5 14ALC05, Flex 5 15ALC05 | GJCN22WW |
IdeaPad 1-11ADA05 Laptop | BIOS Update for Windows 10 (64-bit) - ideapad 1-11ADA05, ideapad 1-14ADA05 | FQCN19WW |
IdeaPad 1-11IGL05 Laptop | BIOS Update for Windows 10 (64-bit) - ideapad 1-11IGL05, ideapad 1-14IGL05 | DWCN20WW |
IdeaPad 1-14ADA05 Laptop | BIOS Update for Windows 10 (64-bit) - ideapad 1-11ADA05, ideapad 1-14ADA05 | FQCN19WW |
IdeaPad 1-14IGL05 Laptop | BIOS Update for Windows 10 (64-bit) - ideapad 1-11IGL05, ideapad 1-14IGL05 | DWCN20WW |
S940-14IIL Laptop (ideapad) | BIOS Update for Windows 10 (64-bit) - Yoga S940-14IIL, ideapad S940-14IIL | BQCN32WW |
S940-14IWL Laptop (ideapad) | BIOS Update for Windows 10 (64-bit) - S940-14IWL, Yoga S940-14IWL | AKCN42WW |
Slim 1-11AST-05 Laptop (ideapad) | BIOS Update for Windows 10 (64-bit) - Slim 1-11AST-05, Slim 1-14AST-05 | CWCN23WW |
Slim 1-14AST-05 Laptop (ideapad) | BIOS Update for Windows 10 (64-bit) - Slim 1-11AST-05, Slim 1-14AST-05 | CWCN23WW |
V130-15IGM Laptop (Lenovo) | BIOS Update for Windows 10 (64-bit) - V130-15IGM | 6VCN42WW |
V130-15IKB Laptop (Lenovo) | BIOS Update for Windows 10 (64-bit) - V130-15IKB | 8VCN29WW |
V330-15IKB Laptop (Lenovo) | BIOS Update for Windows 7 (32-bit & 64-bit), Windows 10 (64-bit) - V330-15IKB, V330-15ISK | 6SCN54WW |
V330-15ISK Laptop (Lenovo) | BIOS Update for Windows 7 (32-bit & 64-bit), Windows 10 (64-bit) - V330-15IKB, V330-15ISK | 6SCN54WW |
Yoga C940-15IRH Laptop (ideapad) | BIOS Update for Windows 10 (64-bit) - Yoga C940-15IRH | BSCN35WW |
Yoga S730-13IML Laptop (Lenovo) | BIOS Update for Windows 10 (64-bit) - Yoga S730-13IML,ideapad 730S-13IML | BRCN18WW |
Yoga S940-14IIL Laptop (Lenovo) | BIOS Update for Windows 10 (64-bit) - Yoga S940-14IIL, ideapad S940-14IIL | BQCN32WW |
Yoga S940-14IWL Laptop (Lenovo) | BIOS Update for Windows 10 (64-bit) - S940-14IWL, Yoga S940-14IWL | AKCN42WW |
Product | Component | CVE-2021-3452 | CVE-2021-3453 |
11e Yoga Gen 6 (Type 20SE 20SF) Laptop (ThinkPad) | BIOS Update (Utility & Bootable CD) for Windows 10 (64-bit) - ThinkPad 11e Yoga Gen 6 | R18ET26W | Not Affected |
Helix (Type 20CG, 20CH) Laptop (ThinkPad) | BIOS Update (Utility & Bootable CD) for Windows 10 (64-bit), 8.1 (64-bit) - ThinkPad Helix (Type 20CG, 20CH) | Not Affected | N17ETB4W |
T550 Laptop (ThinkPad) | BIOS Update (Utility & Bootable CD) for Windows 10, 8.1 (64-bit), 7 (32-bit, 64-bit) - ThinkPad T550, W550s | Not Affected | N11ET53W |
W550s Laptop (ThinkPad) | BIOS Update (Utility & Bootable CD) for Windows 10, 8.1 (64-bit), 7 (32-bit, 64-bit) - ThinkPad T550, W550s | Not Affected | N11ET53W |
X1 Carbon 3rd Gen (Type 20BS, 20BT) Laptop (ThinkPad) | BIOS Update (Utility & Bootable CD) for Windows 10, 8.1 (64-bit), 7 (32-bit, 64-bit) - ThinkPad X1 Carbon (Type 20BS, 20BT) | Not Affected | N14ET55W |
X250 Laptop (ThinkPad) | BIOS Update (Utility & Bootable CD) for Windows 10/8.1/7 (64-bit), 7 (32-bit) - ThinkPad X250 | Not Affected | N10ET62W(1.41) |
Yoga 15 Laptop (ThinkPad) | BIOS Update (Utility & Bootable CD) for Windows 10, 8.1, 7 (64-bit) - ThinkPad Yoga 15 | Not Affected | N19ET65W |
Your feedback helps to improve the overall experience