Lenovo Super File Hijack Vulnerability Could Allow Local Attacker to Execute Code with Elevated Privileges
CVE-2024-4089

7.8HIGH

Key Information:

Vendor
Lenovo
Status
Vendor
CVE Published:
11 October 2024

Summary

A vulnerability exists in Lenovo Super File that allows a local attacker to exploit a DLL hijacking flaw. By placing a malicious DLL in a specific location, the attacker can manipulate the application into loading the malicious file instead of the legitimate one. This may result in the execution of arbitrary code with elevated privileges, posing significant risks to system integrity and user data. Users are strongly recommended to apply updates and security patches provided by Lenovo to mitigate this vulnerability and secure their systems.

Affected Version(s)

SuperFile 0 < 2.4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks ggid7788 for reporting this issue.
.