Learn about CVE-2020-8322, a vulnerability in Lenovo BIOS Legacy USB driver allowing arbitrary code execution. Find mitigation steps and firmware update details.
A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
Understanding CVE-2020-8322
This CVE-2020-8322 vulnerability affects Lenovo BIOS in various versions.
What is CVE-2020-8322?
CVE-2020-8322 is a vulnerability in the SMI callback function of the Legacy USB driver in certain Lenovo Notebook and ThinkStation models, potentially enabling attackers to execute arbitrary code.
The Impact of CVE-2020-8322
The impact of this vulnerability is rated as MEDIUM with a CVSS base score of 6.4. It poses a high risk to confidentiality, integrity, and availability of affected systems, requiring high privileges for exploitation.
Technical Details of CVE-2020-8322
This section provides detailed technical information about the CVE-2020-8322 vulnerability.
Vulnerability Description
The vulnerability lies in the SMI callback function within the Legacy USB driver, allowing for potential arbitrary code execution on impacted Lenovo Notebook and ThinkStation models.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited locally with high attack complexity and impact, requiring no user interaction. Attackers with high privileges can execute arbitrary code, potentially compromising system confidentiality, integrity, and availability.
Mitigation and Prevention
Protecting systems from CVE-2020-8322 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates