CVE-2018-16091: Lenovo System Management Module Firmware
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.
Affected products
- Lenovo System Management Module Firmware: before 1.06 (fixed in 1.06)
Published 2018-11-27. Last modified 2026-06-17.