Learn about CVE-2022-3430, a vulnerability in Lenovo WMI Setup driver on certain Notebook devices enabling privilege escalation to modify secure boot settings.
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Understanding CVE-2022-3430
This section provides insights into the impact, technical details, and mitigation strategies related to CVE-2022-3430.
What is CVE-2022-3430?
CVE-2022-3430 is a potential vulnerability in the WMI Setup driver on certain Lenovo Notebook devices that could enable a malicious actor with elevated privileges to alter secure boot settings through NVRAM variable modifications.
The Impact of CVE-2022-3430
The vulnerability poses a medium-level risk with a CVSS base score of 6.7. It has a high impact on availability, confidentiality, and integrity, requiring high privileges and no user interaction for exploitation.
Technical Details of CVE-2022-3430
Below are specific technical details related to the vulnerability:
Vulnerability Description
The vulnerability arises in the WMI Setup driver on select Lenovo Notebook devices, allowing attackers with elevated privileges to tamper with secure boot settings via NVRAM variable adjustments.
Affected Systems and Versions
The vulnerability impacts various versions of the BIOS on Lenovo consumer Notebook devices.
Exploitation Mechanism
The attack complexity is low, with a local attack vector. The availability, confidentiality, and integrity are highly impacted with high privileges required and no user interaction.
Mitigation and Prevention
To safeguard against CVE-2022-3430, users and organizations are advised to take the following steps:
Immediate Steps to Take
Long-Term Security Practices
Incorporate regular firmware updates and security patches, conduct security audits, and restrict privileged access to mitigate similar vulnerabilities.
Patching and Updates
Ensure timely installation of firmware updates and security patches provided by Lenovo to address CVE-2022-3430.