Home
MEDIUM: 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NMEDIUM: 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
Any version before 1.0.0.138
affected
Default status
unaffected
Any version before 1.0.0.138
affected
Description
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.
Problem types
CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Product status
Any version before 1.0.0.138
Any version before 1.0.0.138
Credits
Lenovo thanks Manuel Kiesel (cyllective AG) for reporting this issue.
References
support.lenovo.com/us/en/product_security/LEN-213044
iknow.lenovo.com.cn/detail/438815