Home
HIGH: 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NHIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 10.2501.20.0
affected
Default status
unaffected
Any version before 20.2506.39.0
affected
Description
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
Problem types
CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Product status
Any version before 10.2501.20.0
Any version before 20.2506.39.0
Credits
Lenovo thanks Bryan Alexander of Atredis Partners for reporting this issue.
References
support.lenovo.com/us/en/product_security/LEN-196648