A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.
Credits
Lenovo thanks Souhardya Sardar of Cyberstanc for reporting this issue.