Medium severity6.7NVD Advisory· Published Jan 26, 2023· Updated Jun 17, 2026
CVE-2022-1891
CVE-2022-1891
Description
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Affected products
9- cpe:2.3:o:lenovo:thinkbook_14-iil_firmware:*:*:*:*:*:*:*:*Range: <djcn28ww
- cpe:2.3:o:lenovo:thinkbook_14-iml_firmware:*:*:*:*:*:*:*:*Range: <cjcn38ww
- cpe:2.3:o:lenovo:thinkbook_15-iil_firmware:*:*:*:*:*:*:*:*Range: <djcn28ww
- cpe:2.3:o:lenovo:thinkbook_15-iml_firmware:*:*:*:*:*:*:*:*Range: <cjcn38ww
- cpe:2.3:o:lenovo:yoga_c640-13iml_firmware:*:*:*:*:*:*:*:*Range: <chcn28ww
- cpe:2.3:o:lenovo:yoga_c640-13iml_lte_firmware:*:*:*:*:*:*:*:*Range: <chcn28ww
Patches
Vulnerability mechanics
References
1- support.lenovo.com/us/en/product_security/LEN-91369nvdVendor Advisory
News mentions
0No linked articles in our index yet.