CVE-2017-3740: Lenovo Active Protection System
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.
Affected products
- Lenovo Active Protection System: version 1.00b only; version 1.01b only; version 1.20b only; version 1.21 only; version 1.22 only; version 1.23 only; …
Published 2017-06-04. Last modified 2026-06-17.