Home
MEDIUM: 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:NHIGH: 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HDefault status
unaffected
Any version before 1.0.8.15
affected
Default status
unaffected
Any version before 1.0.8.15
affected
Description
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
Problem types
CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Product status
Any version before 1.0.8.15
Any version before 1.0.8.15
Credits
Lenovo thanks Manuel Kiesel (cyllective AG) for reporting these issues.
References
support.lenovo.com/us/en/product_security/LEN-213044
iknow.lenovo.com.cn/detail/438815