DLL Search Path Vulnerability in Lenovo Installation Packages
CVE-2019-6173
6.7MEDIUM
Summary
A DLL search path vulnerability exists in certain Lenovo installation packages that may allow an attacker with existing administrative privileges to escalate their privileges during the installation process. This issue, present in versions prior to 1.2.9.3, poses a significant risk as it could potentially enable unauthorized execution of malicious DLL files, compromising the system's integrity. Users are urged to update to the latest version to mitigate this security risk.
Affected Version(s)
Installation Packages < 1.2.9.3
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Eran Shimony at CyberArk Labs for reporting this issue