A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.
Solution:
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.