Please note: This website includes an accessibility system. Press Control-F11 to adjust the website to the visually impaired who are using a screen reader; Press Control-F10 to open an accessibility menu.

Lenovo BIOS Vulnerabilities (July 2021)

Lenovo BIOS Vulnerabilities (July 2021)

Lenovo BIOS Vulnerabilities (July 2021)

Lenovo Security Advisory: LEN-65529

Potential Impact: Privilege escalation

Severity: Medium

Scope of Impact: Lenovo-specific

CVE Identifier: CVE-2021-3452, CVE-2021-3453, CVE-2021-3614

 

Summary Description:

The following vulnerabilities were reported in Lenovo BIOS:

CVE-2021-3452: A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVE-2021-3453: Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

CVE-2021-3614: A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage.

 

Mitigation Strategy for Customers (what you should do to protect yourself):

Update system firmware to the version (or newer) indicated for your model in the Product Impact section.

 

Product Impact:

To download the version specified for your product below, follow these steps:

Navigate to the Drivers & Software support site for your product:

  1. Search for your product by name or machine type.
  2. Click Drivers & Software on the left menu panel.
  3. Click on Manual Update to browse by Component type.
  4. Compare the minimum fix version for your product from the applicable product table below with the latest version posted on the support site.

Lenovo also offers tools to assist with update management as an alternative to the manual steps described above. Refer to the following for additional help:

PC Products and Software: https://support.lenovo.com/us/en/solutions/ht504759

Server and Enterprise Software: https://support.lenovo.com/us/en/solutions/lnvo-lxcaupd and https://datacentersupport.lenovo.com/us/en/documents/lnvo-center

 

Click below links to view affected products:

Desktop

Lenovo Notebook

ThinkPad

 

Acknowledgement:

CVE-2021-3452, CVE-2021-3453: Lenovo thanks Binarly efiXplorer team for reporting these issues.

CVE-2021-3614: Lenovo thanks Tim Boyd, NCC Group for reporting this issue.

 

Revision History:

Revision Date Description
3 2021-11-15 Updated Desktop and Lenovo Notebook
2 2021-08-06 Updated Lenovo Notebook, ThinkPad
1 2021-07-13 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.

 

Product Impact:

Desktop

Product Component CVE-2021-3453
ideacentre AIO 5-24IMB05 Desktop BIOS for Windows 10 (64-bit) - ideacentre AIO 5-24IMB05 Desktop O4UKT32A
ideacentre AIO 5-27IMB05 Desktop BIOS for Windows 10 (64-bit) - ideacentre AIO 5-27IMB05 Desktop O4VKT33A

 

Lenovo Notebook

Product Component CVE-2021-3614
100e 2nd Gen Notebook (Lenovo) (Type 82GJ) BIOS Update for Windows 10 (64-bit) - Lenovo 100e 2nd Gen (MT:82GJ), Lenovo 300e 2nd Gen (MT:82GK) FRCN20WW
300e 2nd Gen Notebook (Lenovo) (Type 82GK) BIOS Update for Windows 10 (64-bit) - Lenovo 100e 2nd Gen (MT:82GJ), Lenovo 300e 2nd Gen (MT:82GK) FRCN20WW
730S-13IML Laptop (ideapad) BIOS Update for Windows 10 (64-bit) - Yoga S730-13IML,ideapad 730S-13IML BRCN18WW
Flex 5-14ALC05 Laptop (ideapad) BIOS Update for Windows 10 (64-bit) - Flex 5 14ALC05, Flex 5 15ALC05 GJCN22WW
Flex 5-15ALC05 Laptop (ideapad) BIOS Update for Windows 10 (64-bit) - Flex 5 14ALC05, Flex 5 15ALC05 GJCN22WW
IdeaPad 1-11ADA05 Laptop BIOS Update for Windows 10 (64-bit) - ideapad 1-11ADA05, ideapad 1-14ADA05 FQCN19WW
IdeaPad 1-11IGL05 Laptop BIOS Update for Windows 10 (64-bit) - ideapad 1-11IGL05, ideapad 1-14IGL05 DWCN20WW
IdeaPad 1-14ADA05 Laptop BIOS Update for Windows 10 (64-bit) - ideapad 1-11ADA05, ideapad 1-14ADA05 FQCN19WW
IdeaPad 1-14IGL05 Laptop BIOS Update for Windows 10 (64-bit) - ideapad 1-11IGL05, ideapad 1-14IGL05 DWCN20WW
S940-14IIL Laptop (ideapad) BIOS Update for Windows 10 (64-bit) - Yoga S940-14IIL, ideapad S940-14IIL BQCN32WW
S940-14IWL Laptop (ideapad) BIOS Update for Windows 10 (64-bit) - S940-14IWL, Yoga S940-14IWL AKCN42WW
Slim 1-11AST-05 Laptop (ideapad) BIOS Update for Windows 10 (64-bit) - Slim 1-11AST-05, Slim 1-14AST-05 CWCN23WW
Slim 1-14AST-05 Laptop (ideapad) BIOS Update for Windows 10 (64-bit) - Slim 1-11AST-05, Slim 1-14AST-05 CWCN23WW
V130-15IGM Laptop (Lenovo) BIOS Update for Windows 10 (64-bit) - V130-15IGM 6VCN42WW
V130-15IKB Laptop (Lenovo) BIOS Update for Windows 10 (64-bit) - V130-15IKB 8VCN29WW
V330-15IKB Laptop (Lenovo) BIOS Update for Windows 7 (32-bit & 64-bit), Windows 10 (64-bit) - V330-15IKB, V330-15ISK 6SCN54WW
V330-15ISK Laptop (Lenovo) BIOS Update for Windows 7 (32-bit & 64-bit), Windows 10 (64-bit) - V330-15IKB, V330-15ISK 6SCN54WW
Yoga C940-15IRH Laptop (ideapad) BIOS Update for Windows 10 (64-bit) - Yoga C940-15IRH BSCN35WW
Yoga S730-13IML Laptop (Lenovo) BIOS Update for Windows 10 (64-bit) - Yoga S730-13IML,ideapad 730S-13IML BRCN18WW
Yoga S940-14IIL Laptop (Lenovo) BIOS Update for Windows 10 (64-bit) - Yoga S940-14IIL, ideapad S940-14IIL BQCN32WW
Yoga S940-14IWL Laptop (Lenovo) BIOS Update for Windows 10 (64-bit) - S940-14IWL, Yoga S940-14IWL AKCN42WW

 

ThinkPad

Product Component CVE-2021-3452 CVE-2021-3453
11e Yoga Gen 6 (Type 20SE 20SF) Laptop (ThinkPad) BIOS Update (Utility & Bootable CD) for Windows 10 (64-bit) - ThinkPad 11e Yoga Gen 6 R18ET26W Not Affected
Helix (Type 20CG, 20CH) Laptop (ThinkPad) BIOS Update (Utility & Bootable CD) for Windows 10 (64-bit), 8.1 (64-bit) - ThinkPad Helix (Type 20CG, 20CH) Not Affected N17ETB4W
T550 Laptop (ThinkPad) BIOS Update (Utility & Bootable CD) for Windows 10, 8.1 (64-bit), 7 (32-bit, 64-bit) - ThinkPad T550, W550s Not Affected N11ET53W
W550s Laptop (ThinkPad) BIOS Update (Utility & Bootable CD) for Windows 10, 8.1 (64-bit), 7 (32-bit, 64-bit) - ThinkPad T550, W550s Not Affected N11ET53W
X1 Carbon 3rd Gen (Type 20BS, 20BT) Laptop (ThinkPad) BIOS Update (Utility & Bootable CD) for Windows 10, 8.1 (64-bit), 7 (32-bit, 64-bit) - ThinkPad X1 Carbon (Type 20BS, 20BT) Not Affected N14ET55W
X250 Laptop (ThinkPad) BIOS Update (Utility & Bootable CD) for Windows 10/8.1/7 (64-bit), 7 (32-bit) - ThinkPad X250 Not Affected N10ET62W(1.41)
Yoga 15 Laptop (ThinkPad) BIOS Update (Utility & Bootable CD) for Windows 10, 8.1, 7 (64-bit) - ThinkPad Yoga 15 Not Affected N19ET65W

Alias Id:LEN-65529
Document ID:PS500426
Original Publish Date:07/13/2021
Last Modified Date:11/15/2021