CVE-2023-4029 (k14_type_21cu_firmware, k14_type_21cv_firmware, thinkpad_e14_gen_3_firmware, thinkpad_e15_gen_3_firmware, thinkpad_l13_gen_2_firmware, thinkpad_l13_gen_3_firmware, thinkpad_l13_gen_4_firmware, thinkpad_l13_yoga_gen_2_firmware, thinkpad_l13_yoga_gen_3_firmware, thinkpad_l13_yoga_gen_4_firmware, thinkpad_l14_gen_2_firmware, thinkpad_l14_gen_3_firmware, thinkpad_l14_gen_4_firmware, thinkpad_l15_gen_2_firmware, thinkpad_l15_gen_3_firmware, thinkpad_l15_gen_4_firmware, thinkpad_p14s_gen_2_firmware, thinkpad_s2_gen_6_firmware, thinkpad_s2_gen_7_firmware, thinkpad_s2_gen_8_firmware, thinkpad_s2_yoga_gen_6_firmware, thinkpad_s2_yoga_gen_7_firmware, thinkpad_s2_yoga_gen_8_firmware, thinkpad_t14_gen_2_firmware, thinkpad_t14s_gen_2_firmware, thinkpad_x13_gen_2_firmware)

A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.Read More