SARA / Free Tools / CVE / CVE-2024-3100

CVE-2024-3100 — A potential buffer overflow vulnerability was reported in some Lenovo Notebook p

A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.

CVSS
6.7 MEDIUM
EPSS
10.00% (top 71.90%)
CWE
CWE-121
Published
2024-09-13T17:26:33.357Z
Last modified
2024-09-17T14:38:51.949Z
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

01What is this vulnerability?

A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.

02Affected products

VendorProductVersions
Lenovo100w Gen 3 Laptop (Lenovo) BIOS0
Lenovo100w Gen 4 Laptop (Lenovo) BIOS0
Lenovo13w Yoga (Type 82S1, 82S2) Laptop (Lenovo) BIOS0
Lenovo13w Yoga Gen 2 (Type 82YR, 82YS) Laptop (Lenovo) BIOS0
Lenovo14W Gen 2 Laptop (Lenovo) BIOS0
Lenovo300w Gen 3 Laptop (Lenovo) BIOS0
Lenovo300w Yoga Gen 4 Laptop (Lenovo) BIOS0
Lenovo500w Yoga Gen 4 Laptop (Lenovo) BIOS0
LenovoFlex 514ITL05 Laptop (ideapad) BIOS — 0
LenovoFlex 515ITL05 Laptop (ideapad) BIOS — 0
LenovoIdeaPad 1 14ALC7 Laptop BIOS0
LenovoIdeaPad 1 15ALC7 Laptop BIOS0
LenovoIdeaPad 111IGL05 Laptop BIOS — 0
LenovoIdeaPad 114IGL05 Laptop BIOS — 0
LenovoIdeaPad 3 14ABA7 Laptop BIOS0
LenovoIdeaPad 3 15ABA7 Laptop BIOS0
LenovoIdeaPad 3 17ABA7 Laptop BIOS0
LenovoIdeaPad 314ALC6 Laptop BIOS — 0
LenovoIdeaPad 315ALC6 Laptop BIOS — 0
LenovoIdeaPad 317ALC6 Laptop BIOS — 0
Lenovoideapad 515ALC05 Laptop BIOS — 0
LenovoIdeaPad Flex 5 14ABR8 BIOS0
LenovoIdeaPad Flex 5 14ALC7 Laptop BIOS0
LenovoIdeaPad Flex 5 14IAU7 Laptop BIOS0
LenovoIdeaPad Flex 5 14IRU8 BIOS0
LenovoIdeaPad Flex 5 16ABR8 BIOS0
LenovoIdeaPad Flex 5 16ALC7 BIOS0
LenovoIdeaPad Flex 5 16IAU7 BIOS0
LenovoIdeaPad Flex 5 16IRU8 BIOS0
LenovoIdeaPad Slim 3 14ABR8 BIOS0
LenovoIdeaPad Slim 3 14AMN8 BIOS0
LenovoIdeaPad Slim 3 15ABR8 BIOS0
LenovoIdeaPad Slim 3 15AMN8 BIOS0
LenovoIdeaPad Slim 3 16ABR8 BIOS0
LenovoIdeaPad Slim 5 Light 14ABR8 BIOS0
LenovoK14 G2 IRU BIOS0
LenovoLenovo Flex 7 14IAU7 BIOS0
LenovoLenovo Flex 7 14IRU8 BIOS0
LenovoLenovo V14 G3 ABA Laptop BIOS0
LenovoLenovo V14 G4 ABP BIOS0
LenovoLenovo V14 G4 AMN BIOS0
LenovoLenovo V15 G3 ABA Laptop BIOS0
LenovoLenovo V15 G4 ABP BIOS0
LenovoLenovo V15 G4 AMN BIOS0
LenovoThinkBook 13s G4 ARB BIOS0
LenovoThinkBook 13s G4 IAP BIOS0
LenovoThinkBook 13x G2 IAP Laptop BIOS0
LenovoThinkBook 14 G6 ABP BIOS0
LenovoThinkBook 14 G6 IRL BIOS0
LenovoThinkBook 16 G6 ABP BIOS0

03Active exploitation status

Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.

04Recommended remediation

05Technical details

For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.

06Detection signatures

Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:

Open in Sigma generator →

07Related CVEs

No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.

08Timeline

09References

Want this in your SOAR or SIEM?
SARA's API returns EPSS, CVSS, KEV, and an analyst-grade summary in one call.
Read the API reference →