CVE Feed

    Dashboard / CVE / CVE-2016-8224

    CVE-2016-8224

    A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.

    Published:Nov 29, 2016
    Last Modified:Apr 12, 2025
    EPS:Nov 29, 2016
    EPSS Score:0.00042
    CVSS Score:4.4

    Affected Products

    Vendor
    Lenovo
    Product
    Bios
    Vendor
    Lenovo
    Product
    Notebook 110 14ibr
    Vendor
    Lenovo
    Product
    Notebook 110 14ibr Bios
    Vendor
    Lenovo
    Product
    Notebook 110 15ibr
    Vendor
    Lenovo
    Product
    Notebook 110 15ibr Bios
    Vendor
    Lenovo
    Product
    Notebook B70 80
    Vendor
    Lenovo
    Product
    Notebook B70 80 Bios
    Vendor
    Lenovo
    Product
    Notebook E31 80
    Vendor
    Lenovo
    Product
    Notebook E31 80 Bios
    Vendor
    Lenovo
    Product
    Notebook E40 80
    Vendor
    Lenovo
    Product
    Notebook E40 80 Bios
    Vendor
    Lenovo
    Product
    Notebook E41 80
    Vendor
    Lenovo
    Product
    Notebook E41 80 Bios
    Vendor
    Lenovo
    Product
    Notebook E51 80
    Vendor
    Lenovo
    Product
    Notebook E51 80 Bios
    Vendor
    Lenovo
    Product
    Notebook G40 80
    Vendor
    Lenovo
    Product
    Notebook G40 80 Bios
    Vendor
    Lenovo
    Product
    Notebook G50 80
    Vendor
    Lenovo
    Product
    Notebook G50 80 Bios
    Vendor
    Lenovo
    Product
    Notebook G50 80 Touch
    Vendor
    Lenovo
    Product
    Notebook G50 80 Touch Bios
    Vendor
    Lenovo
    Product
    Notebook Ideapad 300 14ibr
    Vendor
    Lenovo
    Product
    Notebook Ideapad 300 14ibr Bios
    Vendor
    Lenovo
    Product
    Notebook Ideapad 300 14isk
    Vendor
    Lenovo
    Product
    Notebook Ideapad 300 14isk Bios
    Vendor
    Lenovo
    Product
    Notebook Ideapad 300 15ibr
    Vendor
    Lenovo
    Product
    Notebook Ideapad 300 15ibr Bios
    Vendor
    Lenovo
    Product
    Notebook Ideapad 300 15isk
    Vendor
    Lenovo
    Product
    Notebook Ideapad 300 15isk Bios
    Vendor
    Lenovo
    Product
    Notebook Ideapad 300 17isk
    Vendor
    Lenovo
    Product
    Notebook Ideapad 300 17isk Bios
    Vendor
    Lenovo
    Product
    Notebook Ideapad 510s 12isk
    Vendor
    Lenovo
    Product
    Notebook Ideapad 510s 12isk Bios
    Vendor
    Lenovo
    Product
    Notebook K21 80
    Vendor
    Lenovo
    Product
    Notebook K21 80 Bios
    Vendor
    Lenovo
    Product
    Notebook K41 80
    Vendor
    Lenovo
    Product
    Notebook K41 80 Bios
    Vendor
    Lenovo
    Product
    Notebook Miix 710 12ikb
    Vendor
    Lenovo
    Product
    Notebook Miix 710 12ikb Bios
    Vendor
    Lenovo
    Product
    Notebook Xiaoxin Air 12
    Vendor
    Lenovo
    Product
    Notebook Xiaoxin Air 12 Bios
    Vendor
    Lenovo
    Product
    Notebook Yoga 510 14isk
    Vendor
    Lenovo
    Product
    Notebook Yoga 510 14isk Bios
    Vendor
    Lenovo
    Product
    Notebook Yoga 510 15isk
    Vendor
    Lenovo
    Product
    Notebook Yoga 510 15isk Bios
    Vendor
    Lenovo
    Product
    Notebook Yoga 710 11ikb
    Vendor
    Lenovo
    Product
    Notebook Yoga 710 11ikb Bios
    Vendor
    Lenovo
    Product
    Notebook Yoga 710 11isk
    Vendor
    Lenovo
    Product
    Notebook Yoga 710 11isk Bios
    Vendor
    Lenovo
    Product
    Notebook Yoga 900 13isk
    Vendor
    Lenovo
    Product
    Notebook Yoga 900 13isk Bios
    Vendor
    Lenovo
    Product
    Notebook Yoga 900s 12isk
    Vendor
    Lenovo
    Product
    Notebook Yoga 900s 12isk Bios
    Vendor
    Lenovo
    Product
    Thinkserver Ts150
    Vendor
    Lenovo
    Product
    Thinkserver Ts150 Bios
    Vendor
    Lenovo
    Product
    Thinkserver Ts450
    Vendor
    Lenovo
    Product
    Thinkserver Ts450 Bios

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High