CVE-2024-7756: Lenovo 10w Firmware

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.

Affected products

  • Lenovo 10w Firmware
  • Lenovo 10w Type 82st, 82su Laptop Lenovo BIOS
  • Lenovo l390 Type 20nr, 20ns Laptops Thinkpad BIOS: before 1.47 (fixed in 1.47)
  • Lenovo l390 Yoga Type 20nt, 20nu Laptops Thinkpad BIOS: before 1.47 (fixed in 1.47)
  • Lenovo Thinkpad l390 Yoga Firmware: before 1.47 (fixed in 1.47)

Published 2024-09-13. Last modified 2026-06-17.