Lenovo Super File Hijack Vulnerability Could Allow Local Attacker to Execute Code with Elevated Privileges
CVE-2024-4089

7.8HIGH

Key Information:

Vendor

Lenovo

Status
Vendor
CVE Published:
11 October 2024

What is CVE-2024-4089?

A vulnerability exists in Lenovo Super File that allows a local attacker to exploit a DLL hijacking flaw. By placing a malicious DLL in a specific location, the attacker can manipulate the application into loading the malicious file instead of the legitimate one. This may result in the execution of arbitrary code with elevated privileges, posing significant risks to system integrity and user data. Users are strongly recommended to apply updates and security patches provided by Lenovo to mitigate this vulnerability and secure their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SuperFile 0 < 2.4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks ggid7788 for reporting this issue.
.