Elevated Privileges Vulnerability in Lenovo System Update
CVE-2022-0354

7.3HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
22 April 2022

Summary

A vulnerability exists in Lenovo System Update that allows a local user with interactive access to execute code with elevated privileges. This situation arises when the user installs a System Update package released prior to February 25, 2022, which triggers a command prompt window during the process. Exploitation of this vulnerability could lead to unauthorized actions being performed with elevated permissions, potentially compromising the system's integrity.

Affected Version(s)

System Update various

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Daniel Feichter (@VirtualAllocEx) at Infosec Tirol for reporting this issue.
.