Lenovo BIOS Local Privileged Disclosure: SMRAM Address Leak
CVE-2026-10588 Published on July 16, 2026
A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.
Vulnerability Analysis
CVE-2026-10588 is exploitable with local system access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Exposure of Sensitive System Information to an Unauthorized Control Sphere
The application does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the application does.
Products Associated with CVE-2026-10588
Want to know whenever a new CVE is published for Lenovo products? stack.watch will email you.
Affected Versions
Lenovo Yoga Pro 7 15IPH11 BIOS:- Before TNCN37WW is affected.
- Before S4CN62WW is affected.
- Before and including TPCN27WW is affected.
- Before and including T8CN19WW is affected.
- Before and including U5CN07WW is affected.
- Before and including TYCN15WW is affected.
- Before SUCN18WW is affected.
- Before and including QEME23WW is affected.
- Before SMCN20WW is affected.
- Before and including RECN14WW is affected.
- Before SJCN17WW is affected.
- Before L1CN72WW is affected.
- Before and including QWCN34WW is affected.
- Before and including S2CN15WW is affected.
- Before and including RYCN22WW is affected.
- Before and including QNCN28WW is affected.
- Before and including S9CN13WW is affected.
- Before R7CN26WW is affected.
- Before and including RLCN21WW is affected.
- Before RGCN35WW is affected.
- Before and including N2CN26WW is affected.
- Before and including NXCN20WW is affected.
- Before P2CN27WW is affected.
- Before N0CN35WW is affected.
- Before and including MECN68WW is affected.
- Before and including LPCN45WW is affected.
- Before and including LUCN47WW is affected.
- Before and including MACN33WW is affected.
- Before and including P8CN42WW is affected.
- Before and including LPCN59WW is affected.
- Before MCCN39WW is affected.
- Before PMCN38WW is affected.
- Before and including MBCN33WW is affected.
- Before LTCN44WW is affected.
- Before and including KZCN46WW is affected.
- Before L1CN51WW is affected.
- Before L4CN31WW is affected.
- Before and including LPCN59WW is affected.
- Before and including JKCN49WW is affected.
- Before KACN29WW is affected.
- Before P5CN31WW is affected.
- Before HTCN49WW is affected.
- Before and including NKCN30WW is affected.
- Before R2CN57WW is affected.
- Before and including RXCN18WW is affected.
- Before and including Q6CN26WW is affected.
- Before and including Q7CN31WW is affected.
- Before and including QDCN23WW is affected.
- Before and including PTCN14WW is affected.
- Before RHCN20WW is affected.
- Before and including QECN21WW is affected.
- Before QUCN20WW is affected.
- Before QBCN30WW is affected.
- Before and including R1CN24WW is affected.
- Before PJCN18WW is affected.
- Before and including Q9CN22WW is affected.
- Before and including NVCN24WW is affected.
- Before and including PZCN27WW is affected.
- Before and including Q8CN17WW is affected.
- Before and including NNCN31WW is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.