Buffer Overflow Vulnerability in Lenovo System Update
CVE-2018-9063
7.8HIGH
Summary
The Lenovo System Update application contains a vulnerability in its MapDrv component (C:\Program Files\Lenovo\System Update\mapdrv.exe) that can be exploited by an attacker through the submission of excessively large user IDs or passwords. This exploitation could lead to overrun of the program's buffer, resulting in undefined behaviors including the potential execution of arbitrary code. Importantly, the vulnerability does not grant additional privileges beyond those already held by the user running the MapDrv process.
Affected Version(s)
Lenovo System Update Earlier than 5.07.0072
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved