Junglewise Threat Intelligence

CVE-2025-10238: Lenovo ThinkPad BIOS out-of-bounds write in SMM

CVE-2025-10238 · Severity: medium · CVSS 6.7 · Published 2026-06-10

Vendors: Lenovo.

Executive brief

A security vulnerability has been identified in the BIOS firmware of several Lenovo ThinkPad laptop models. The BIOS is the fundamental software that starts the computer and manages hardware before the operating system loads. If exploited, this flaw could allow a user with administrative access to the machine to gain even deeper control over the system, potentially bypassing security protections and compromising the integrity of the device's operations.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists within the BIOS firmware of various Lenovo ThinkPad products. The flaw is located in the handling of memory operations, where insufficient boundary checks allow data to be written outside of intended buffers. An attacker must already possess high privileges (administrative/root) on the local system to exploit this vulnerability. Successful exploitation allows for code execution within System Management Mode (SMM), a highly privileged execution environment that operates independently of the operating system, effectively granting the attacker persistent and stealthy control over the hardware. Users are advised to update their BIOS to the latest version provided by Lenovo.

Affected products

  • Lenovo ThinkPad BIOS

Timeline

  • 2026-06-10: advisory: Initial advisory published by Lenovo and NVD.

References