Privilege Elevation Vulnerability in Lenovo Vantage SystemUpdate Plugin
CVE-2022-3701
7.8HIGH
Summary
A privilege elevation vulnerability has been identified in the Lenovo Vantage SystemUpdate plugin, specifically in version 2.0.0.212 and earlier. This vulnerability could allow a local attacker to leverage this flaw to execute arbitrary code with elevated privileges, potentially leading to unauthorized access and control over affected systems. It is essential for users to ensure they are using the latest version of the software to mitigate the risk associated with this vulnerability.
Affected Version(s)
Vantage SystemUpdate Plugin < 2.0.0.213
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Nils Ole Timm for reporting this issue.