Home
MEDIUM: 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NMEDIUM: 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
Any version before 1.1.0.1111
affected
Description
An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
Problem types
CWE-59: Improper Link Resolution Before File Access ('Link Following')
Product status
Any version before 1.1.0.1111
Credits
Lenovo thanks Alex Lee Tsz Hin @PwCHK and Manuel Kiesel (cyllective AG) / John Ostrowski (Compass Security) for reporting this issue.
References
support.lenovo.com/us/en/product_security/LEN-208293