CVE-2022-1892 is a high-severity buffer overflow vulnerability in the SystemBootManagerDxe driver affecting various Lenovo Notebook products. An attacker with local privileges could exploit this flaw to execute arbitrary code, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community and media attention, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< frcn23wwCPE matchmatch criteria | cpe:2.3:o:lenovo:100e_2nd_gen_firmware:*:*:*:*:*:*:*:* | ||
< gacn38wwCPE matchmatch criteria | cpe:2.3:o:lenovo:100w_gen_3_firmware:*:*:*:*:*:*:*:* | ||
< jacn31wwCPE matchmatch criteria | cpe:2.3:o:lenovo:13w_yoga_firmware:*:*:*:*:*:*:*:* | ||
< h0cn21wwCPE matchmatch criteria | cpe:2.3:o:lenovo:14w_gen_2_firmware:*:*:*:*:*:*:*:* | ||
< frcn23wwCPE matchmatch criteria | cpe:2.3:o:lenovo:300e_2nd_gen_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.