CVE-2017-3754

MEDIUM

Lenovo Notebook Systems - Privilege Escalation

Title source: llm
STIX 2.1

Description

Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0004
EPSS Percentile 13.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
lenovo/bios
Lenovo Group Ltd./Lenovo Notebook BIOS Various
Published Jul 17, 2017
Tracked Since Feb 18, 2026