Skip to main content

Multi-Vendor BIOS Security Vulnerabilities (September 2022) CVE-2021-28216, CVE-2022-40134, CVE-2022-40135, CVE-2022-40136, CVE-2022-40137


Link State
Forum|alt.badge.img+11

 

Multi-Vendor BIOS Security Vulnerabilities (September 2022) - Lenovo Support US

Lenovo has tracked the following vulnerabilities CVE-2022-40134, CVE-2022-40135, and CVE-2022-40136.

They are related to bugs and vulnerabilities that allow escalation privilege to read SMM memory,DOS, information disclosure.

There are bugs in SMI Set BIOS password SMI handler, Smart USB SMI handler used to configure WMI settings.

4 vulnerabilities were fixed by Lenovo this time, CVE-2022-40137 has the highest severity.

Threats to UEFI (BIOS) run at the beginning of the boot process , and therefore very dangerous, before control is transferred to the O.S. in this way they bypass almost all security ssystems.

Update BIOS and firmware where available.

 

 

3 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8512 comments
  • September 15, 2022

Thanks for sharing this.  We use Lenovo here at work so I better pass this along to Security to check in to and update my laptop if needed.  😎


wolff.mateus
Forum|alt.badge.img+11
  • Veeam Vanguard
  • 542 comments
  • September 15, 2022

Thanks for share! So many laptops here too.

Time to check it...


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments
  • September 15, 2022

Thanks for the heads up! 


Comment