CVE-2017-3753 Vulnerability Details

  /     /     /  

CVE-2017-3753 Metadata Quick Info

CVE Published: 10/08/2017 | CVE Updated: 16/09/2024 | CVE Year: 2017
Source: lenovo | Vendor: Lenovo Group Ltd. | Product: Desktop and Notebook BIOS
Status : PUBLISHED

CVE-2017-3753 Description

A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Execution of code in System Management Mode by an attacker with local administrative access
Source: Lenovo Group Ltd.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).