CVE-2017-3753: Lenovo 63 Firmware

Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.

Affected products

  • Lenovo 63 Firmware: version fckt78a only
  • Lenovo h50-30g Firmware: version fckt78a only
  • Lenovo Ideacentre 300-20ish Firmware: affected versions not specified
  • Lenovo Ideacentre 300s-11ish Firmware: affected versions not specified
  • Lenovo Ideacentre 510s-08ish Firmware: affected versions not specified
  • Lenovo Ideacentre 510s-23isu Firmware: version o2ekt24a only
  • Lenovo Ideacentre 700 Firmware: affected versions not specified
  • Lenovo m4500 Firmware: version fckt78a only
  • Lenovo m4500 Id Firmware: version fckt78a only
  • Lenovo m4550 Id Firmware: version fckt78a only
  • Lenovo s200z Firmware: version m09kt33a only
  • Lenovo s500 Firmware: version m0kkt24a only
  • Lenovo Thinkcentre e73 Firmware: version fckt78a only
  • Lenovo Thinkcentre e73s Firmware: version fckt78a only
  • Lenovo Thinkcentre e73z (aio) Firmware: version fgkt49a only
  • Lenovo Thinkcentre e74 Firmware: version m05kt54a only
  • Lenovo Thinkcentre e74s Firmware: version m05kt54a only
  • Lenovo Thinkcentre e74z Firmware: version fvkt48a only
  • Lenovo Thinkcentre e75 T/s Firmware: affected versions not specified
  • Lenovo Thinkcentre e79 Firmware: version m0lkt12a only
  • Lenovo Thinkcentre e93 Firmware: version fbktc5a only
  • Lenovo Thinkcentre e93z (aio) Firmware: version ffkt43a only
  • Lenovo Thinkcentre Edge 62z Firmware: version f8kt40a only
  • Lenovo Thinkcentre m4500k Firmware: version fckt78a only
  • Lenovo Thinkcentre m4500q Firmware: version fhkt66a only
  • and 86 more

Published 2017-08-10. Last modified 2026-06-17.