Lucene search

K
lenovoLenovoLENOVO:PS500073-NOSID
HistoryNov 29, 2016 - 12:00 a.m.

Intel Management Engine protection not set on some Lenovo Notebook and ThinkServer systems - us

2016-11-2900:00:00
support.lenovo.com
32

0.0004 Low

EPSS

Percentile

12.6%

Lenovo Security Advisory: LEN-9903

Potential Impact: Denial of service or privilege escalation by an attacker with administrative access

Severity: Medium

**Scope of Impact:**Industry-Wide

**CVE Identifier:**CVE-2016-8224

Summary Description:

A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.

The Intel Management Engine (ME) is a set of hardware features developed by Intel that enable administrators to manage, repair and protect computers on their networks. During the manufacturing process, a setting is configured on the manufacturing line that locks regions of memory used by the ME and prevents them from being reconfigured. Lenovo has discovered that this protection was not enabled on certain Lenovo systems.

Mitigation Strategy for Customers (what you should do to protect yourself):

Update your system to the latest BIOS level by following the links below.

Product Impact:

0.0004 Low

EPSS

Percentile

12.6%

Related for LENOVO:PS500073-NOSID