Arbitrary Code Execution Vulnerability in Lenovo Notebook and ThinkStation SMI Callback Function

Arbitrary Code Execution Vulnerability in Lenovo Notebook and ThinkStation SMI Callback Function

CVE-2020-8321 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.

Learn more about our Web Application Penetration Testing UK.