CVE-2017-3753 is a medium-severity vulnerability affecting certain Lenovo products utilizing American Megatrends, Inc. (AMI) UEFI (BIOS) code. An attacker with administrative privileges or physical access can execute specially crafted code to bypass system protections like Device Guard and Hyper-V. The CVSS score is 6.8, indicating high impact on confidentiality, integrity, and availability, but requiring physical access or administrative privileges. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it did receive some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:lenovo:ideacentre_300-20ish_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:lenovo:ideacentre_300s-11ish_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:lenovo:ideacentre_510s-08ish_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:lenovo:ideacentre_700_firmware:-:*:*:*:*:*:*:* | ||
fckt78aCPE matchmatch criteria | cpe:2.3:o:lenovo:63_firmware:fckt78a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.