Home

Description

During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.

PUBLISHED Reserved 2025-09-10 | Published 2026-06-10 | Updated 2026-06-10 | Assigner lenovo




HIGH: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

MEDIUM: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-327: Use of a Broken or Risky Cryptographic Algorithm

Product status

Default status
unaffected

Any version before 1.11
affected

Default status
unaffected

Any version before 1.15
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.40
affected

Default status
unaffected

Any version before 1.11
affected

Default status
unaffected

Any version before UEFI BIOS V1.22/ECP V1.13
affected

Default status
unaffected

Any version before 1.15
affected

Default status
unaffected

Any version before 1.14
affected

Default status
unaffected

Any version before 1.13
affected

Default status
unaffected

Any version before 1.09
affected

Default status
unaffected

Any version before 1.09
affected

Default status
unaffected

Any version before 1.46
affected

Default status
unaffected

Any version before 1.26
affected

Default status
unaffected

Any version before 1.37
affected

Default status
unaffected

Any version before 1.65/1.13
affected

Default status
unaffected

Any version before 1.37
affected

Default status
unaffected

Any version before 1.28
affected

Default status
unaffected

Any version before 1.47
affected

Default status
unaffected

Any version before 1.39 / 1.15
affected

Default status
unaffected

Any version before BIOS: 1.66 / ECFW: 1.10
affected

Default status
unaffected

Any version before BIOS: 1.99/ ECFW: 1.58
affected

Default status
unaffected

Any version before 1.22
affected

Default status
unaffected

Any version before 1.52
affected

Default status
unaffected

Any version before 1.23
affected

Default status
unaffected

Any version before 1.34
affected

Default status
unaffected

Any version before 1.24
affected

Default status
unaffected

Any version before 1.29 / 1.11
affected

Default status
unaffected

Any version before 1.28
affected

Default status
unaffected

Any version before 1.27
affected

Default status
unaffected

Any version before 1.38
affected

Default status
unaffected

Any version before 1.62/1.12
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.39
affected

Default status
unaffected

Any version before 1.21
affected

Default status
unaffected

Any version before 1.15
affected

Default status
unaffected

Any version before 1.27
affected

Default status
unaffected

Any version before 1.47/1.27
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.30 / 1.15
affected

Default status
unaffected

Any version before 1.51
affected

Default status
unaffected

Any version before 1.76
affected

Default status
unaffected

Any version before 1.49
affected

Default status
unaffected

Any version before 1.44
affected

Default status
unaffected

Any version before 1.25
affected

Default status
unaffected

Any version before 1.31
affected

Default status
unaffected

Any version before 1.33 / 1.21
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.53
affected

Default status
unaffected

Any version before 1.36
affected

Default status
unaffected

Any version before 1.38/1.36
affected

Default status
unaffected

Any version before 1.76
affected

Default status
unaffected

Any version before 1.52/ 1.28
affected

Default status
unaffected

Any version before 1.65
affected

Default status
unaffected

Any version before 1.36
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.36
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.33
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.34 / 1.19
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.38
affected

Default status
unaffected

Any version before 1.69
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.17
affected

Default status
unaffected

Any version before 1.73
affected

Default status
unaffected

Any version before 1.12
affected

Default status
unaffected

Any version before 1.08
affected

Default status
unaffected

Any version before 1.69/1.21
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.38 / 1.22
affected

Default status
unaffected

Any version before 1.38
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.58 / 1.18
affected

Default status
unaffected

Any version before 1.41
affected

Default status
unaffected

Any version before 2.06 / 1.23
affected

Default status
unaffected

Any version before 1.67 / 1.56
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version before 1.85/1.26
affected

Default status
unaffected

Any version before 1.56 / 1.26
affected

Default status
unaffected

Any version before 1.53
affected

Default status
unaffected

Any version before 1.45
affected

Default status
unaffected

Any version before 1.21
affected

Default status
unaffected

Any version before 1.17
affected

Default status
unaffected

Any version before 1.10
affected

Default status
unaffected

Any version before 1.06
affected

Default status
unaffected

Any version before 1.10
affected

Default status
unaffected

Any version before 1.18 / 1.14
affected

Default status
unaffected

Any version before 1.26
affected

Default status
unaffected

Any version before 1.18
affected

Default status
unaffected

Any version before 1.22 / 1.15
affected

Default status
unaffected

Any version before 1.16
affected

Default status
unaffected

Any version
affected

References

support.lenovo.com/us/en/product_security/LEN-218282 vendor-advisory

cve.org (CVE-2025-10237)

nvd.nist.gov (CVE-2025-10237)

Download JSON