Privilege Escalation Vulnerability in Lenovo System Interface Foundation
CVE-2020-8319

7.3HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
14 April 2020

Summary

A vulnerability in Lenovo System Interface Foundation prior to version 1.1.19.3 allows authenticated users to exploit privilege escalation. This flaw could enable attackers to execute code with elevated privileges, thereby compromising system integrity and security.

Affected Version(s)

Lenovo System Interface Foundation < 1.1.19.3

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Ceri Coburn at Pen Test Partners for reporting this issue.
.