Home
MEDIUM: 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:NMEDIUM: 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:HDefault status
unaffected
Any version before 1.6.5.2
affected
Description
An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges.
Problem types
CWE-276: Incorrect Default Permissions
Product status
Any version before 1.6.5.2
Credits
Lenovo thanks Sheikh Rishad for reporting this issue.
References
support.lenovo.com/us/en/product_security/LEN-198729