Lucene search

K
cveLenovoCVE-2017-3767
HistoryNov 13, 2017 - 4:29 p.m.

CVE-2017-3767

2017-11-1316:29:00
lenovo
web.nvd.nist.gov
32
vulnerability
local privilege escalation
realtek audio driver
lenovo thinkpad
code execution
administrative privileges

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

A local privilege escalation vulnerability was identified in the Realtek audio driver versions prior to 6.0.1.8224 in some Lenovo ThinkPad products. An attacker with local privileges could execute code with administrative privileges.

Affected configurations

Nvd
Node
lenovothinkpad_10Match-
OR
lenovothinkpad_11eMatch-
OR
lenovothinkpad_13Match-
OR
lenovothinkpad_l450Match-
OR
lenovothinkpad_l460Match-
OR
lenovothinkpad_l470_kblMatch-
OR
lenovothinkpad_l470_sklMatch-
OR
lenovothinkpad_l560Match-
OR
lenovothinkpad_p50Match-
OR
lenovothinkpad_p50sMatch-
OR
lenovothinkpad_p51sMatch-
OR
lenovothinkpad_p70Match-
OR
lenovothinkpad_p71Match-
OR
lenovothinkpad_s1Match-
OR
lenovothinkpad_s1_yogaMatch-
OR
lenovothinkpad_s1_yoga_12Match-
OR
lenovothinkpad_s2Match-
OR
lenovothinkpad_t440Match-
OR
lenovothinkpad_t440pMatch-
OR
lenovothinkpad_t440sMatch-
OR
lenovothinkpad_t450Match-
OR
lenovothinkpad_t450sMatch-
OR
lenovothinkpad_t460Match-
OR
lenovothinkpad_t460pMatch-
OR
lenovothinkpad_t460sMatch-
OR
lenovothinkpad_t470Match-
OR
lenovothinkpad_t470pMatch-
OR
lenovothinkpad_t470s_sklMatch-
OR
lenovothinkpad_t540pMatch-
OR
lenovothinkpad_t550Match-
OR
lenovothinkpad_t560Match-
OR
lenovothinkpad_t570Match-
OR
lenovothinkpad_w540Match-
OR
lenovothinkpad_w541Match-
OR
lenovothinkpad_w550sMatch-
OR
lenovothinkpad_x1_carbonMatch-
OR
lenovothinkpad_x1_tabletMatch-
OR
lenovothinkpad_x1_yogaMatch-
OR
lenovothinkpad_x1cMatch-
OR
lenovothinkpad_x240Match-
OR
lenovothinkpad_x240sMatch-
OR
lenovothinkpad_x250Match-
OR
lenovothinkpad_x260Match-
OR
lenovothinkpad_x270_kblMatch-
OR
lenovothinkpad_x270_sklMatch-
OR
lenovothinkpad_yoga_11eMatch-
AND
realtekaudio_driver_firmwareRange<6.0.1.8224
VendorProductVersionCPE
lenovothinkpad_10-cpe:2.3:h:lenovo:thinkpad_10:-:*:*:*:*:*:*:*
lenovothinkpad_11e-cpe:2.3:h:lenovo:thinkpad_11e:-:*:*:*:*:*:*:*
lenovothinkpad_13-cpe:2.3:h:lenovo:thinkpad_13:-:*:*:*:*:*:*:*
lenovothinkpad_l450-cpe:2.3:h:lenovo:thinkpad_l450:-:*:*:*:*:*:*:*
lenovothinkpad_l460-cpe:2.3:h:lenovo:thinkpad_l460:-:*:*:*:*:*:*:*
lenovothinkpad_l470_kbl-cpe:2.3:h:lenovo:thinkpad_l470_kbl:-:*:*:*:*:*:*:*
lenovothinkpad_l470_skl-cpe:2.3:h:lenovo:thinkpad_l470_skl:-:*:*:*:*:*:*:*
lenovothinkpad_l560-cpe:2.3:h:lenovo:thinkpad_l560:-:*:*:*:*:*:*:*
lenovothinkpad_p50-cpe:2.3:h:lenovo:thinkpad_p50:-:*:*:*:*:*:*:*
lenovothinkpad_p50s-cpe:2.3:h:lenovo:thinkpad_p50s:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 471

CNA Affected

[
  {
    "product": "Realtek Audio Driver",
    "vendor": "Lenovo Group Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "Earlier than 6.0.1.8224"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Related for CVE-2017-3767