CVE-2022-3430

Published Jan 23, 2023

Last updated 2 years ago

Overview

Description
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Source
psirt@lenovo.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
6.7
Impact score
5.9
Exploitability score
0.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
MEDIUM

Weaknesses

nvd@nist.gov
CWE-276
psirt@lenovo.com
CWE-276

Social media

Hype score
Not currently trending

Configurations