CVE-2017-3753

A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.

Published: 2017-08-09 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2017-3753 is rated Moderate Risk (41.5/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.52%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2017-3753

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.04% 0.52% +0.47%
2 2026-03-25 0.06% 0.04% -0.02%
3 2023-03-07 0.06%

Full EPSS history (5 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2017-3753

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.8 3.0 MEDIUM
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:P)
Hands-on access—USB, keyboard, opening the case—not something you do purely over the wire.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.9 5.9 [email protected]
7.2 2.0 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.9 10.0 [email protected]

Weakness enumeration for CVE-2017-3753

Affected software / configurations for CVE-2017-3753

Vendor Product Version Raw CPE
lenovo ideacentre_300-20ish_firmware cpe:2.3:o:lenovo:ideacentre_300-20ish_firmware:-:*:*:*:*:*:*:*
lenovo ideacentre_300s-11ish_firmware cpe:2.3:o:lenovo:ideacentre_300s-11ish_firmware:-:*:*:*:*:*:*:*
lenovo ideacentre_510s-08ish_firmware cpe:2.3:o:lenovo:ideacentre_510s-08ish_firmware:-:*:*:*:*:*:*:*
lenovo ideacentre_700_firmware cpe:2.3:o:lenovo:ideacentre_700_firmware:-:*:*:*:*:*:*:*
lenovo 63_firmware fckt78a cpe:2.3:o:lenovo:63_firmware:fckt78a:*:*:*:*:*:*:*
lenovo h50-30g_firmware fckt78a cpe:2.3:o:lenovo:h50-30g_firmware:fckt78a:*:*:*:*:*:*:*
lenovo m4500_firmware fckt78a cpe:2.3:o:lenovo:m4500_firmware:fckt78a:*:*:*:*:*:*:*
lenovo m4500_id_firmware fckt78a cpe:2.3:o:lenovo:m4500_id_firmware:fckt78a:*:*:*:*:*:*:*
lenovo m4550_id_firmware fckt78a cpe:2.3:o:lenovo:m4550_id_firmware:fckt78a:*:*:*:*:*:*:*
lenovo s500_firmware m0kkt24a cpe:2.3:o:lenovo:s500_firmware:m0kkt24a:*:*:*:*:*:*:*
lenovo v320-15iap_firmware cpe:2.3:o:lenovo:v320-15iap_firmware:-:*:*:*:*:*:*:*
lenovo thinkcentre_e73_firmware fckt78a cpe:2.3:o:lenovo:thinkcentre_e73_firmware:fckt78a:*:*:*:*:*:*:*
lenovo thinkcentre_e73s_firmware fckt78a cpe:2.3:o:lenovo:thinkcentre_e73s_firmware:fckt78a:*:*:*:*:*:*:*
lenovo thinkcentre_e74_firmware m05kt54a cpe:2.3:o:lenovo:thinkcentre_e74_firmware:m05kt54a:*:*:*:*:*:*:*
lenovo thinkcentre_e74s_firmware m05kt54a cpe:2.3:o:lenovo:thinkcentre_e74s_firmware:m05kt54a:*:*:*:*:*:*:*
lenovo thinkcentre_e75_t\/s_firmware cpe:2.3:o:lenovo:thinkcentre_e75_t\/s_firmware:-:*:*:*:*:*:*:*
lenovo thinkcentre_e79_firmware m0lkt12a cpe:2.3:o:lenovo:thinkcentre_e79_firmware:m0lkt12a:*:*:*:*:*:*:*
lenovo thinkcentre_e93_firmware fbktc5a cpe:2.3:o:lenovo:thinkcentre_e93_firmware:fbktc5a:*:*:*:*:*:*:*
lenovo thinkcentre_m4500k_firmware fckt78a cpe:2.3:o:lenovo:thinkcentre_m4500k_firmware:fckt78a:*:*:*:*:*:*:*
lenovo thinkcentre_m4500q_firmware fhkt66a cpe:2.3:o:lenovo:thinkcentre_m4500q_firmware:fhkt66a:*:*:*:*:*:*:*
lenovo thinkcentre_m4500t\/s_firmware fckt78a cpe:2.3:o:lenovo:thinkcentre_m4500t\/s_firmware:fckt78a:*:*:*:*:*:*:*
lenovo thinkcentre_m4600t\/s_firmware m05kt54a cpe:2.3:o:lenovo:thinkcentre_m4600t\/s_firmware:m05kt54a:*:*:*:*:*:*:*
lenovo thinkcentre_m600_firmware m00kt44a cpe:2.3:o:lenovo:thinkcentre_m600_firmware:m00kt44a:*:*:*:*:*:*:*
lenovo thinkcentre_m610_firmware cpe:2.3:o:lenovo:thinkcentre_m610_firmware:-:*:*:*:*:*:*:*
lenovo thinkcentre_m6500t\/s_firmware fbktc5a cpe:2.3:o:lenovo:thinkcentre_m6500t\/s_firmware:fbktc5a:*:*:*:*:*:*:*
lenovo thinkcentre_m6600_firmware fwkt39a cpe:2.3:o:lenovo:thinkcentre_m6600_firmware:fwkt39a:*:*:*:*:*:*:*
lenovo thinkcentre_m6600q_firmware fwkt39a cpe:2.3:o:lenovo:thinkcentre_m6600q_firmware:fwkt39a:*:*:*:*:*:*:*
lenovo thinkcentre_m6600t\/s_firmware fwkt39a cpe:2.3:o:lenovo:thinkcentre_m6600t\/s_firmware:fwkt39a:*:*:*:*:*:*:*
lenovo thinkcentre_m700_firmware m05kt54a cpe:2.3:o:lenovo:thinkcentre_m700_firmware:m05kt54a:*:*:*:*:*:*:*
lenovo thinkcentre_m710t\/s_firmware cpe:2.3:o:lenovo:thinkcentre_m710t\/s_firmware:-:*:*:*:*:*:*:*
lenovo thinkcentre_m715q_firmware cpe:2.3:o:lenovo:thinkcentre_m715q_firmware:-:*:*:*:*:*:*:*
lenovo thinkcentre_m72e_firmware f1kt71a cpe:2.3:o:lenovo:thinkcentre_m72e_firmware:f1kt71a:*:*:*:*:*:*:*
lenovo thinkcentre_m73_firmware fckt78a cpe:2.3:o:lenovo:thinkcentre_m73_firmware:fckt78a:*:*:*:*:*:*:*
lenovo thinkcentre_m73p_firmware fbktc5a cpe:2.3:o:lenovo:thinkcentre_m73p_firmware:fbktc5a:*:*:*:*:*:*:*
lenovo thinkcentre_m79_firmware m0lkt12a cpe:2.3:o:lenovo:thinkcentre_m79_firmware:m0lkt12a:*:*:*:*:*:*:*
lenovo thinkcentre_m800_firmware fwkt39a cpe:2.3:o:lenovo:thinkcentre_m800_firmware:fwkt39a:*:*:*:*:*:*:*
lenovo thinkcentre_m83_firmware fbktcga cpe:2.3:o:lenovo:thinkcentre_m83_firmware:fbktcga:*:*:*:*:*:*:*
lenovo thinkcentre_m8500t\/s_firmware fbktc5a cpe:2.3:o:lenovo:thinkcentre_m8500t\/s_firmware:fbktc5a:*:*:*:*:*:*:*
lenovo thinkcentre_m8600t\/s_firmware fwkt39a cpe:2.3:o:lenovo:thinkcentre_m8600t\/s_firmware:fwkt39a:*:*:*:*:*:*:*
lenovo thinkcentre_m900_firmware fwkt39a cpe:2.3:o:lenovo:thinkcentre_m900_firmware:fwkt39a:*:*:*:*:*:*:*
lenovo thinkcentre_m910t\/s_firmware cpe:2.3:o:lenovo:thinkcentre_m910t\/s_firmware:-:*:*:*:*:*:*:*
lenovo thinkcentre_m910q_firmware cpe:2.3:o:lenovo:thinkcentre_m910q_firmware:-:*:*:*:*:*:*:*
lenovo thinkcentre_m910x_firmware cpe:2.3:o:lenovo:thinkcentre_m910x_firmware:-:*:*:*:*:*:*:*
lenovo thinkcentre_m92_firmware 9skt95a cpe:2.3:o:lenovo:thinkcentre_m92_firmware:9skt95a:*:*:*:*:*:*:*
lenovo thinkcentre_m92p_firmware 9skt95a cpe:2.3:o:lenovo:thinkcentre_m92p_firmware:9skt95a:*:*:*:*:*:*:*
lenovo thinkcentre_m93_firmware fbktc5a cpe:2.3:o:lenovo:thinkcentre_m93_firmware:fbktc5a:*:*:*:*:*:*:*
lenovo thinkcentre_m93p_firmware fbktc5a cpe:2.3:o:lenovo:thinkcentre_m93p_firmware:fbktc5a:*:*:*:*:*:*:*
lenovo yangtian_afh110_firmware m05kt73a cpe:2.3:o:lenovo:yangtian_afh110_firmware:m05kt73a:*:*:*:*:*:*:*
lenovo yangtian_afh81_firmware fckt80a cpe:2.3:o:lenovo:yangtian_afh81_firmware:fckt80a:*:*:*:*:*:*:*
lenovo yangtian_afq150_firmware fwkt57a cpe:2.3:o:lenovo:yangtian_afq150_firmware:fwkt57a:*:*:*:*:*:*:*
lenovo yangtian_mc_carrizo-l_firmware cpe:2.3:o:lenovo:yangtian_mc_carrizo-l_firmware:-:*:*:*:*:*:*:*
lenovo yangtian_mc_godavari_firmware m0lkt13a cpe:2.3:o:lenovo:yangtian_mc_godavari_firmware:m0lkt13a:*:*:*:*:*:*:*
lenovo yangtian_mc_h110_firmware m05kt61a cpe:2.3:o:lenovo:yangtian_mc_h110_firmware:m05kt61a:*:*:*:*:*:*:*
lenovo yangtian_mc_h81_firmware fckt80a cpe:2.3:o:lenovo:yangtian_mc_h81_firmware:fckt80a:*:*:*:*:*:*:*
lenovo yangtian_me\/we_h110_firmware m05kt61a cpe:2.3:o:lenovo:yangtian_me\/we_h110_firmware:m05kt61a:*:*:*:*:*:*:*
lenovo yangtian_mf\/wf_h81_firmware fckt80a cpe:2.3:o:lenovo:yangtian_mf\/wf_h81_firmware:fckt80a:*:*:*:*:*:*:*
lenovo ideacentre_510s-23isu_firmware o2ekt24a cpe:2.3:o:lenovo:ideacentre_510s-23isu_firmware:o2ekt24a:*:*:*:*:*:*:*
lenovo s200z_firmware m09kt33a cpe:2.3:o:lenovo:s200z_firmware:m09kt33a:*:*:*:*:*:*:*
lenovo thinkcentre_e73z_\(aio\)_firmware fgkt49a cpe:2.3:o:lenovo:thinkcentre_e73z_\(aio\)_firmware:fgkt49a:*:*:*:*:*:*:*
lenovo thinkcentre_e74z_firmware fvkt48a cpe:2.3:o:lenovo:thinkcentre_e74z_firmware:fvkt48a:*:*:*:*:*:*:*
lenovo thinkcentre_e93z_\(aio\)_firmware ffkt43a cpe:2.3:o:lenovo:thinkcentre_e93z_\(aio\)_firmware:ffkt43a:*:*:*:*:*:*:*
lenovo thinkcentre_edge_62z_firmware f8kt40a cpe:2.3:o:lenovo:thinkcentre_edge_62z_firmware:f8kt40a:*:*:*:*:*:*:*
lenovo thinkcentre_m700z_firmware fvkt48a cpe:2.3:o:lenovo:thinkcentre_m700z_firmware:fvkt48a:*:*:*:*:*:*:*
lenovo thinkcentre_m7200z_firmware fgkt46a cpe:2.3:o:lenovo:thinkcentre_m7200z_firmware:fgkt46a:*:*:*:*:*:*:*
lenovo thinkcentre_m7250z_firmware fgkt46a cpe:2.3:o:lenovo:thinkcentre_m7250z_firmware:fgkt46a:*:*:*:*:*:*:*
lenovo thinkcentre_m7300z_firmware fvkt42a cpe:2.3:o:lenovo:thinkcentre_m7300z_firmware:fvkt42a:*:*:*:*:*:*:*
lenovo thinkcentre_m73z_\(aio\)_firmware fgkt46a cpe:2.3:o:lenovo:thinkcentre_m73z_\(aio\)_firmware:fgkt46a:*:*:*:*:*:*:*
lenovo thinkcentre_m800z_firmware fvkt42a cpe:2.3:o:lenovo:thinkcentre_m800z_firmware:fvkt42a:*:*:*:*:*:*:*
lenovo thinkcentre_m810z_firmware cpe:2.3:o:lenovo:thinkcentre_m810z_firmware:-:*:*:*:*:*:*:*
lenovo thinkcentre_m8200z_firmware fgkt46a cpe:2.3:o:lenovo:thinkcentre_m8200z_firmware:fgkt46a:*:*:*:*:*:*:*
lenovo thinkcentre_m8250z_firmware fgkt46a cpe:2.3:o:lenovo:thinkcentre_m8250z_firmware:fgkt46a:*:*:*:*:*:*:*
lenovo thinkcentre_m8300z_firmware fvkt42a cpe:2.3:o:lenovo:thinkcentre_m8300z_firmware:fvkt42a:*:*:*:*:*:*:*
lenovo thinkcentre_m8350z_firmware fvkt42a cpe:2.3:o:lenovo:thinkcentre_m8350z_firmware:fvkt42a:*:*:*:*:*:*:*
lenovo thinkcentre_m83z_\(aio\)_firmware fvkt42a cpe:2.3:o:lenovo:thinkcentre_m83z_\(aio\)_firmware:fvkt42a:*:*:*:*:*:*:*
lenovo thinkcentre_m900z_firmware fukt39a cpe:2.3:o:lenovo:thinkcentre_m900z_firmware:fukt39a:*:*:*:*:*:*:*
lenovo thinkcentre_m9500z_firmware fukt44a cpe:2.3:o:lenovo:thinkcentre_m9500z_firmware:fukt44a:*:*:*:*:*:*:*
lenovo thinkcentre_m9550z_firmware fukt44a cpe:2.3:o:lenovo:thinkcentre_m9550z_firmware:fukt44a:*:*:*:*:*:*:*
lenovo thinkcentre_x1_aio_firmware m0hkt32a cpe:2.3:o:lenovo:thinkcentre_x1_aio_firmware:m0hkt32a:*:*:*:*:*:*:*
lenovo yangtian_s3040_firmware fgkt49a cpe:2.3:o:lenovo:yangtian_s3040_firmware:fgkt49a:*:*:*:*:*:*:*
lenovo yangtian_s800_firmware ffkt43a cpe:2.3:o:lenovo:yangtian_s800_firmware:ffkt43a:*:*:*:*:*:*:*

References for CVE-2017-3753

cvelogic Threat Intelligence