CVE-2024-7756 - CVE House
Back to Database
Status published Medium CVE-2024-7756

A potential vulnerability was reported in the ThinkPad L390 Yoga...

Vulnerability Description

A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-7756

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Lenovo thanks Warren Togami for reporting this issue.

Affected Vendor

Affected Software

10w (Type 82ST, 82SU) Laptop (Lenovo) BIOS, L390 (type 20NR, 20NS) Laptops (ThinkPad) BIOS, L390 Yoga (type 20NT, 20NU) Laptops (ThinkPad) BIOS
Vulnerable Versions:
0

Timeline

Official Publish: September 13th, 2024
Last Modified: September 16th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.