CVE-2023-45077
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Nov 8, 2023
Updated: Nov 16, 2023
CWE ID 125
Summary
CVE-2023-45077 is a memory leakage vulnerability affecting the 534D0740 DXE driver. This issue allows a local attacker with elevated privileges to manipulate NVRAM variables by exploiting the memory leakage. The attacker can potentially write unauthorized data, leading to system instability or unintended behavior. The vulnerability poses a significant risk and requires prompt patching to prevent potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- ThinkCentre
- Lenovo Legion T7-34imz5 Firmware
- Lenovo IdeaCentre
Affected Vendors
- Lenovo Companies