Vulnerabilities > Lenovo > Thinkpad X1 Yoga GEN 2 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-04-22 CVE-2022-1107 Improper Privilege Management vulnerability in Lenovo products
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
local
low complexity
lenovo CWE-269
6.7