PatchSiren

Lenovo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Lenovo CVE published 2017-01-26

CVE-2016-8227

CVE-2016-8227 is a high-severity local privilege escalation vulnerability in Lenovo Transition on Lenovo Yoga, Flex, and Miix systems running Windows. According to NVD, a local user could execute code with elevated privileges. Lenovo’s advisory is linked from the official NVD record and should be used to confirm affected systems and mitigation steps.

MEDIUM Lenovo CVE published 2017-01-26

CVE-2016-8226

CVE-2016-8226 is a firmware denial-of-service issue in Lenovo BIOS for System X M5, M6, and X6 platforms. According to the NVD record, an administrator with high privileges can trigger a DoS condition while updating a UEFI data structure.

HIGH Lenovo CVE published 2017-01-26

CVE-2016-8225

CVE-2016-8225 is a local privilege escalation issue in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21. The weakness is an unquoted service path condition (CWE-428), which can allow a local user to execute code with elevated privileges. NVD rates the issue HIGH with CVSS 7.8.