Home
HIGH: 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NHIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 9.0.2530.1027
affected
Default status
unaffected
Any version before 9.0.6.11071
affected
Description
A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions.
Problem types
CWE-427: Uncontrolled Search Path Element
Product status
Any version before 9.0.2530.1027
Any version before 9.0.6.11071
Credits
Lenovo thanks Wanjie from Huazhong University of Science and Technology for reporting this issue.
References
iknow.lenovo.com.cn/detail/435004