CVE-2024-7756: Lenovo 10w Firmware
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.
Affected products
- Lenovo 10w Firmware
- Lenovo 10w Type 82st, 82su Laptop Lenovo BIOS
- Lenovo l390 Type 20nr, 20ns Laptops Thinkpad BIOS: before 1.47 (fixed in 1.47)
- Lenovo l390 Yoga Type 20nt, 20nu Laptops Thinkpad BIOS: before 1.47 (fixed in 1.47)
- Lenovo Thinkpad l390 Yoga Firmware: before 1.47 (fixed in 1.47)
Published 2024-09-13. Last modified 2026-06-17.