ThinkPad Models Vulnerable to Code Execution Exploit via SmmOEMInt15 SMI Handler

ThinkPad Models Vulnerable to Code Execution Exploit via SmmOEMInt15 SMI Handler

CVE-2022-1107 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

Learn more about our Internal Network Penetration Testing.