Privilege Elevation Vulnerability in Lenovo Vantage SystemUpdate Plugin
CVE-2022-3701

7.8HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
27 October 2023

Summary

A privilege elevation vulnerability has been identified in the Lenovo Vantage SystemUpdate plugin, specifically in version 2.0.0.212 and earlier. This vulnerability could allow a local attacker to leverage this flaw to execute arbitrary code with elevated privileges, potentially leading to unauthorized access and control over affected systems. It is essential for users to ensure they are using the latest version of the software to mitigate the risk associated with this vulnerability.

Affected Version(s)

Vantage SystemUpdate Plugin < 2.0.0.213

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Nils Ole Timm for reporting this issue.
.