Home

Description

A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modify data and execute arbitrary code.

PUBLISHED Reserved 2026-01-14 | Published 2026-03-11 | Updated 2026-03-13 | Assigner lenovo




HIGH: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

MEDIUM: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-665: Improper Initialization

Product status

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Credits

Lenovo thanks Krzysztof Okupski of IOActive for reporting this issue. finder

References

support.lenovo.com/us/en/product_security/LEN-213040

cve.org (CVE-2026-0940)

nvd.nist.gov (CVE-2026-0940)

Download JSON