Home

Description

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.

PUBLISHED Reserved 2026-01-30 | Published 2026-03-11 | Updated 2026-03-12 | Assigner lenovo




MEDIUM: 6.9CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

HIGH: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Problem types

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Product status

Default status
unaffected

Any version before 1.0.8.15
affected

Default status
unaffected

Any version before 1.0.8.15
affected

Credits

Lenovo thanks Manuel Kiesel (cyllective AG) for reporting these issues. finder

References

support.lenovo.com/us/en/product_security/LEN-213044

iknow.lenovo.com.cn/detail/438815

cve.org (CVE-2026-1716)

nvd.nist.gov (CVE-2026-1716)

Download JSON