CVE-2023-4028 (13w_yoga_firmware, 13w_yoga_gen_2_firmware, flex_5-14alc05_firmware, flex_5-14are05_firmware, flex_5-14iil05_firmware, flex_5-14itl05_firmware, flex_5-15alc05_firmware, flex_5-15iil05_firmware, flex_5-15itl05_firmware, flex_7_14iru8_firmware, ideapad_1-11ada05_firmware, ideapad_1-11igl05_firmware, ideapad_1-14ada05_firmware, ideapad_1-14igl05_firmware, ideapad_flex_5_14abr8_firmware, ideapad_flex_5_14alc7_firmware, ideapad_flex_5_14iau7_firmware, ideapad_flex_5_14iru8_firmware, ideapad_flex_5_16abr8_firmware, ideapad_flex_5_16alc7_firmware, ideapad_flex_5_16iau7_firmware, ideapad_flex_5_16iru8_firmware, thinkbook_13s_g2_are_firmware, thinkbook_13s_g2_itl_firmware, thinkbook_13s_g3_acn_firmware, thinkbook_13s_g4_iap_firmware, thinkbook_13x_g2_iap_firmware, thinkbook_14s_g2_itl_firmware, yoga_9-15imh5_firmware)

A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.Read More