DLL Search Path Vulnerability in Lenovo PCManager
CVE-2022-0192
7.8HIGH
Summary
A DLL search path vulnerability was discovered in Lenovo's PCManager software prior to version 4.0.40.2175. This vulnerability could potentially allow unauthorized escalation of privileges, enabling adversaries to execute malicious code with elevated permissions. Users are advised to update to the latest version to mitigate this risk.
Affected Version(s)
PCManager < 4.0.40.2175
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Shangji Pang from Topsec Alpha Lab for reporting this issue