Uncontrolled Search Path Vulnerabilities in Lenovo Universal Device Client
CVE-2023-6338
7.8HIGH
Summary
The Lenovo Universal Device Client is impacted by uncontrolled search path vulnerabilities that may allow an attacker with local access to the system to execute arbitrary code with elevated privileges. This situation presents a serious risk, as unauthorized users could manipulate the execution path of applications to run malicious code, potentially leading to further system compromise. Users are advised to apply the necessary security updates and follow best practices to mitigate these risks.
Affected Version(s)
Universal Device Client (UDC) < 23.10
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Moritz Rauch for reporting this issue