Sploit.io - Search

Product: k14_g2_iru_firmware, version: < mmcn36ww

CVE-2024-3100

Severity: MEDIUM

Description: A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.

CVSS Score: 6.7

Priority

B

CISA Data

EPSS Data

  • EPSS: 0.000430000
  • Percentile: 0.110860000
  • Date: 2025-01-09

ExploitDB

No data available.

HackerOne Data

  • Rank: 7450
  • Reports submitted count: 0
  • Unknown: 0
  • None: 0
  • Low: 0
  • Medium: 0
  • High: 0
  • Critical: 0

GitHub PoCs

    Nuclei Templates

    No data available.

    VulnCheck Data

    Affected Products:

    • Lenovo 100w Gen 3 Laptop (Lenovo) BIOS - Versions: 0
    • Lenovo 100w Gen 4 Laptop (Lenovo) BIOS - Versions: 0
    • Lenovo 13w Yoga (Type 82S1, 82S2) Laptop (Lenovo) BIOS - Versions: 0
    • Lenovo 13w Yoga Gen 2 (Type 82YR, 82YS) Laptop (Lenovo) BIOS - Versions: 0
    • Lenovo 14W Gen 2 Laptop (Lenovo) BIOS - Versions: 0
    • Lenovo 300w Gen 3 Laptop (Lenovo) BIOS - Versions: 0
    • Lenovo 300w Yoga Gen 4 Laptop (Lenovo) BIOS - Versions: 0
    • Lenovo 500w Yoga Gen 4 Laptop (Lenovo) BIOS - Versions: 0
    • Lenovo Flex 5-14ITL05 Laptop (ideapad) BIOS - Versions: 0
    • Lenovo Flex 5-15ITL05 Laptop (ideapad) BIOS - Versions: 0
    • Lenovo IdeaPad 1 14ALC7 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad 1 15ALC7 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad 1-11IGL05 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad 1-14IGL05 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad 3 14ABA7 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad 3 15ABA7 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad 3 17ABA7 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad 3-14ALC6 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad 3-15ALC6 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad 3-17ALC6 Laptop BIOS - Versions: 0
    • Lenovo ideapad 5-15ALC05 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad Flex 5 14ABR8 BIOS - Versions: 0
    • Lenovo IdeaPad Flex 5 14ALC7 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad Flex 5 14IAU7 Laptop BIOS - Versions: 0
    • Lenovo IdeaPad Flex 5 14IRU8 BIOS - Versions: 0
    • Lenovo IdeaPad Flex 5 16ABR8 BIOS - Versions: 0
    • Lenovo IdeaPad Flex 5 16ALC7 BIOS - Versions: 0
    • Lenovo IdeaPad Flex 5 16IAU7 BIOS - Versions: 0
    • Lenovo IdeaPad Flex 5 16IRU8 BIOS - Versions: 0
    • Lenovo IdeaPad Slim 3 14ABR8 BIOS - Versions: 0
    • Lenovo IdeaPad Slim 3 14AMN8 BIOS - Versions: 0
    • Lenovo IdeaPad Slim 3 15ABR8 BIOS - Versions: 0
    • Lenovo IdeaPad Slim 3 15AMN8 BIOS - Versions: 0
    • Lenovo IdeaPad Slim 3 16ABR8 BIOS - Versions: 0
    • Lenovo IdeaPad Slim 5 Light 14ABR8 BIOS - Versions: 0
    • Lenovo K14 G2 IRU BIOS - Versions: 0
    • Lenovo Lenovo Flex 7 14IAU7 BIOS - Versions: 0
    • Lenovo Lenovo Flex 7 14IRU8 BIOS - Versions: 0
    • Lenovo Lenovo V14 G3 ABA Laptop BIOS - Versions: 0
    • Lenovo Lenovo V14 G4 ABP BIOS - Versions: 0
    • Lenovo Lenovo V14 G4 AMN BIOS - Versions: 0
    • Lenovo Lenovo V15 G3 ABA Laptop BIOS - Versions: 0
    • Lenovo Lenovo V15 G4 ABP BIOS - Versions: 0
    • Lenovo Lenovo V15 G4 AMN BIOS - Versions: 0
    • Lenovo ThinkBook 13s G4 ARB BIOS - Versions: 0
    • Lenovo ThinkBook 13s G4 IAP BIOS - Versions: 0
    • Lenovo ThinkBook 13x G2 IAP Laptop BIOS - Versions: 0
    • Lenovo ThinkBook 14 G6 ABP BIOS - Versions: 0
    • Lenovo ThinkBook 14 G6 IRL BIOS - Versions: 0
    • Lenovo ThinkBook 16 G6 ABP BIOS - Versions: 0
    • Lenovo ThinkBook 16 G6 IRL BIOS - Versions: 0
    • Lenovo V14 G2-ALC Laptop (Lenovo) BIOS - Versions: 0
    • Lenovo V15 G2-ALC Laptop (Lenovo) BIOS - Versions: 0
    • Lenovo Yoga Slim 7 Pro-14ACH5 Laptop (ideapad) BIOS - Versions: 0
    • Lenovo Yoga Slim 7 Pro-14ACH5 O Laptop (ideapad) BIOS - Versions: 0

    References:

    Risk Assessment

    1. Risk Assessment
    The vulnerability identified as CVE-2024-3100 is a buffer overflow issue affecting the BIOS firmware of multiple Lenovo Notebook products. This vulnerability allows a local attacker with elevated privileges to execute arbitrary code, potentially leading to full system compromise. The CVSS score of 6.7 (MEDIUM) reflects its moderate severity, with high impacts on confidentiality, integrity, and availability. The attack vector is local, requiring high privileges, which reduces the likelihood of widespread exploitation. However, if exploited, the consequences could be severe, including unauthorized access to sensitive data, system manipulation, and disruption of operations. The EPSS score of 0.000430000 indicates a low probability of exploitation in the wild, but the potential impact on affected systems remains significant.

    2. Potential Attack Scenarios
    A potential attack scenario involves an insider threat or a compromised user account with administrative privileges. The attacker could exploit the buffer overflow vulnerability by executing a malicious payload within the BIOS environment. This could be achieved through a crafted firmware update or by leveraging existing administrative tools to trigger the vulnerability. Once exploited, the attacker could gain persistent access to the system, bypassing operating system-level security controls. The outcome could include data exfiltration, installation of malware, or rendering the system inoperable. This scenario is particularly concerning for organizations with sensitive data or critical operations reliant on Lenovo Notebooks.

    3. Mitigation Recommendations
    The primary mitigation for this vulnerability is to update the system firmware to the latest version provided by Lenovo. Affected users should refer to the Lenovo advisory (https://support.lenovo.com/us/en/product_security/LEN-165524) for specific firmware versions and update instructions. Organizations should also enforce strict access controls to limit the number of users with administrative privileges, reducing the attack surface. Additionally, monitoring for unusual system behavior or unauthorized firmware changes can help detect potential exploitation attempts. Regular security audits and employee training on insider threats are also recommended to mitigate risks associated with this vulnerability.

    4. Executive Summary
    CVE-2024-3100 is a buffer overflow vulnerability in the BIOS firmware of certain Lenovo Notebooks, posing a moderate risk to affected systems. While exploitation requires local access and elevated privileges, successful attacks could lead to severe consequences, including data breaches, system manipulation, and operational disruptions. The vulnerability has been assigned a CVSS score of 6.7, reflecting its potential impact on confidentiality, integrity, and availability. Immediate action is recommended, including updating firmware to the latest version and restricting administrative access. Organizations should prioritize this update to protect sensitive data and maintain operational continuity. Addressing this vulnerability is critical to mitigating risks and ensuring the security of Lenovo Notebook systems.