DLL Search Path Vulnerability in Lenovo Installation Packages
CVE-2019-6173

6.7MEDIUM

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
9 June 2020

Summary

A DLL search path vulnerability exists in certain Lenovo installation packages that may allow an attacker with existing administrative privileges to escalate their privileges during the installation process. This issue, present in versions prior to 1.2.9.3, poses a significant risk as it could potentially enable unauthorized execution of malicious DLL files, compromising the system's integrity. Users are urged to update to the latest version to mitigate this security risk.

Affected Version(s)

Installation Packages < 1.2.9.3

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Eran Shimony at CyberArk Labs for reporting this issue
.