Privilege Escalation Vulnerability in Lenovo Fingerprint Manager
CVE-2015-3321

6.7MEDIUM

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
3 October 2017

Summary

The Lenovo Fingerprint Manager prior to version 8.01.42 has a flaw in its Access Control Lists (ACLs), allowing local users to bypass security measures and gain unauthorized privileges through common filesystem commands. This misconfiguration could lead to significant security risks if exploited, enabling attackers to manipulate system permissions.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.