A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Credits
Lenovo thanks Jiawei Yin(@yngweijw) and Menghao Li of IIE varas