DLL Search Path Flaw in Lenovo HardwareScan Plugin Exposes Lenovo Vantage Users to Escalation of Privilege Risks
CVE-2020-8345
7.3HIGH
Summary
A vulnerability exists in the Lenovo HardwareScan Plugin, part of the Lenovo Vantage software, where improper handling of DLL search paths could lead to unauthorized privilege escalation. This flaw affects versions prior to 1.0.46.11, potentially allowing attackers to exploit the system's functionality beyond intended permissions, compromising system integrity and security.
Affected Version(s)
Vantage HardwareScan Plugin < 1.0.46.11
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Security Advisor, Anders Kusk, Improsec ApS for reporting this issue.