A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Solution:
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-94952 | vendor advisory |