Lenovo Lock Screen Hijack Vulnerability Allows Local Attacker to Execute Code with Elevated Privileges
CVE-2024-4132

7.8HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
11 October 2024

Summary

A DLL hijack vulnerability exists in Lenovo Lock Screen, allowing local attackers to exploit the issue for executing arbitrary code with elevated privileges. By placing a malicious DLL in a location that the application accesses, an attacker can gain control over the affected product, potentially leading to unauthorized changes to system configurations or data breaches. This vulnerability underscores the importance of keeping security measures updated and adapting to emerging threats in the cybersecurity landscape.

Affected Version(s)

Lock Screen 0 < 9.0.18

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks ggid7788 for reporting this issue.
.