TOCTOU Vulnerability in Lenovo Vantage SystemUpdate Plugin
CVE-2022-3700

6.1MEDIUM

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
27 October 2023

Summary

A Time of Check Time of Use (TOCTOU) vulnerability exists in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier. This flaw potentially enables a local attacker to exploit the timing discrepancies between the file validation check and its subsequent use, resulting in the deletion of arbitrary files on the system. Such vulnerabilities can pose significant risks to the integrity and availability of data, as unauthorized alterations or deletions may occur, leading to operational disruptions.

Affected Version(s)

Vantage SystemUpdate Plugin < 2.0.0.213

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Nils Ole Timm for reporting this issue.
.