Lenovo Lock Screen Hijack Vulnerability Allows Local Attacker to Execute Code with Elevated Privileges
CVE-2024-4132
7.8HIGH
Summary
A DLL hijack vulnerability exists in Lenovo Lock Screen, allowing local attackers to exploit the issue for executing arbitrary code with elevated privileges. By placing a malicious DLL in a location that the application accesses, an attacker can gain control over the affected product, potentially leading to unauthorized changes to system configurations or data breaches. This vulnerability underscores the importance of keeping security measures updated and adapting to emerging threats in the cybersecurity landscape.
Affected Version(s)
Lock Screen 0 < 9.0.18
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks ggid7788 for reporting this issue.