CVE-2024-3100 is a buffer overflow vulnerability affecting certain Lenovo Notebook products, allowing a local attacker with elevated privileges to execute arbitrary code. It carries a CVSS score of 6.7 (Medium), indicating high impact on confidentiality, integrity, and availability, but requires local access and high privileges. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Lenovo | 100w Gen 3 Laptop (Lenovo) BIOS | >= 0, < GACN48WWCNA affecteddefault unaffected | |
| Lenovo | 100w Gen 4 Laptop (Lenovo) BIOS | >= 0, < L2CN34WW/L3CN34WWCNA affecteddefault unaffected | |
| Lenovo | 13w Yoga (Type 82S1, 82S2) Laptop (Lenovo) BIOS | >= 0, < JACN41WWCNA affecteddefault unaffected | |
| Lenovo | 13w Yoga Gen 2 (Type 82YR, 82YS) Laptop (Lenovo) BIOS | >= 0, < KBCN29WWCNA affecteddefault unaffected | |
| Lenovo | 14W Gen 2 Laptop (Lenovo) BIOS | >= 0, < H0CN29WWCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.