DLL Search Path Flaw in Lenovo HardwareScan Plugin Exposes Lenovo Vantage Users to Escalation of Privilege Risks
CVE-2020-8345

7.3HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
14 October 2020

Summary

A vulnerability exists in the Lenovo HardwareScan Plugin, part of the Lenovo Vantage software, where improper handling of DLL search paths could lead to unauthorized privilege escalation. This flaw affects versions prior to 1.0.46.11, potentially allowing attackers to exploit the system's functionality beyond intended permissions, compromising system integrity and security.

Affected Version(s)

Vantage HardwareScan Plugin < 1.0.46.11

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Security Advisor, Anders Kusk, Improsec ApS for reporting this issue.
.