DLL Search Path Flaw in Lenovo HardwareScan Plugin Exposes Lenovo Vantage Users to Escalation of Privilege Risks
CVE-2020-8345
7.3HIGH
What is CVE-2020-8345?
A vulnerability exists in the Lenovo HardwareScan Plugin, part of the Lenovo Vantage software, where improper handling of DLL search paths could lead to unauthorized privilege escalation. This flaw affects versions prior to 1.0.46.11, potentially allowing attackers to exploit the system's functionality beyond intended permissions, compromising system integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Vantage HardwareScan Plugin < 1.0.46.11
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Security Advisor, Anders Kusk, Improsec ApS for reporting this issue.