A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Solution:
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-94952 | vendor advisory |