Code Execution Vulnerability in Lenovo System Interface Foundation
CVE-2019-6186

8.8HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
19 November 2019

Summary

A security vulnerability has been identified in Lenovo System Interface Foundation versions prior to v1.1.18.3, which could enable an authenticated user to execute arbitrary code with the privileges of another user. This flaw raises concerns regarding unauthorized access and potential manipulation of system functionalities.

Affected Version(s)

Lenovo System Interface Foundation <= 1.1.18.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.