CVE-2017-3756: Lenovo Thinkpad 10 Ella 2

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.

Affected products

  • Lenovo Thinkpad 10 Ella 2
  • Lenovo Thinkpad 10 Ella 2 BIOS: affected versions not specified
  • Lenovo Thinkpad 11e Beema
  • Lenovo Thinkpad 11e Beema BIOS: affected versions not specified
  • Lenovo Thinkpad 11e Braswell
  • Lenovo Thinkpad 11e Braswell BIOS: affected versions not specified
  • Lenovo Thinkpad 11e Broadwell
  • Lenovo Thinkpad 11e Broadwell BIOS: affected versions not specified
  • Lenovo Thinkpad 11e Skylake
  • Lenovo Thinkpad 11e Skylake BIOS: affected versions not specified
  • Lenovo Thinkpad 13e
  • Lenovo Thinkpad 13e BIOS: affected versions not specified
  • Lenovo Thinkpad e450
  • Lenovo Thinkpad e450 BIOS: affected versions not specified
  • Lenovo Thinkpad e450c
  • Lenovo Thinkpad e450c BIOS: affected versions not specified
  • Lenovo Thinkpad e455
  • Lenovo Thinkpad e455 BIOS: affected versions not specified
  • Lenovo Thinkpad e460
  • Lenovo Thinkpad e460 BIOS: affected versions not specified
  • Lenovo Thinkpad e465
  • Lenovo Thinkpad e465 BIOS: affected versions not specified
  • Lenovo Thinkpad e550
  • Lenovo Thinkpad e550 BIOS: affected versions not specified
  • Lenovo Thinkpad e550c
  • and 123 more

Published 2017-08-18. Last modified 2026-06-17.