Home

Description

An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.

PUBLISHED Reserved 2026-01-30 | Published 2026-03-11 | Updated 2026-03-12 | Assigner lenovo




MEDIUM: 6.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

MEDIUM: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Product status

Default status
unaffected

Any version before 1.0.0.138
affected

Default status
unaffected

Any version before 1.0.0.138
affected

Credits

Lenovo thanks Manuel Kiesel (cyllective AG) for reporting this issue. finder

References

support.lenovo.com/us/en/product_security/LEN-213044

iknow.lenovo.com.cn/detail/438815

cve.org (CVE-2026-1717)

nvd.nist.gov (CVE-2026-1717)

Download JSON