Uncontrolled Search Path Vulnerabilities in Lenovo Universal Device Client
CVE-2023-6338

7.8HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
3 January 2024

Summary

The Lenovo Universal Device Client is impacted by uncontrolled search path vulnerabilities that may allow an attacker with local access to the system to execute arbitrary code with elevated privileges. This situation presents a serious risk, as unauthorized users could manipulate the execution path of applications to run malicious code, potentially leading to further system compromise. Users are advised to apply the necessary security updates and follow best practices to mitigate these risks.

Affected Version(s)

Universal Device Client (UDC) < 23.10

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Moritz Rauch for reporting this issue
.