DLL Preloading Vulnerability in Lenovo Driver Management Software
CVE-2021-3633

7.3HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
17 August 2021

Summary

A DLL preloading vulnerability was identified in Lenovo Driver Management, allowing potential privilege escalation for unauthorized users prior to version 2.9.0719.1104. This could lead to unintended execution of malicious code, potentially compromising system integrity.

Affected Version(s)

Driver Management < 2.9.0719.1104

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Guangdong Network Security Emergency Response Center and Sangfor QianLiMu Security Lab – Terminal Security Team for identifying this issue.
.