VYPR
Medium severity6.7NVD Advisory· Published Nov 12, 2021· Updated Jun 17, 2026

CVE-2021-3599

CVE-2021-3599

Description

A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Affected products

135

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.