When "secure" isn't secure at all: High‑impact UEFI vulnerabilities discovered in Lenovo consumer laptops
ESET research discovers vulnerabilities in Lenovo consumer laptop models that allow attackers with admin rights to expose users to firmware-level malware.
Tianocore Pchplatformpolicy Dispatchfunction Pchbioswriteprotect Lenovovariablesmm Swsminumber Services Exitbootservices Development Support Protected Range
Source: welivesecurity.com