CVE-2017-3754

MEDIUM

Lenovo Notebook Systems - Privilege Escalation

Title source: llm

Description

Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.

Scores

CVSS v3 6.7
EPSS 0.0004
EPSS Percentile 13.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
lenovo/bios
Lenovo Group Ltd./Lenovo Notebook BIOS < Various
Published Jul 17, 2017
Tracked Since Feb 18, 2026