CVE-2017-3754
medium
CVSS v3
6.7
CVSS v2
7.2
VIR risk
6.7
Description
Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.
Predictions
Exploit likelihood
66%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@lenovo.com — https://support.lenovo.com/us/en/product_security/LEN-15084
References
Verify integrity in audit chain (admin only). AS-IS.