Information Disclosure Vulnerability in Lenovo's Dolby Vision Provisioning Software
CVE-2024-5474
5.5MEDIUM
Key Information:
- Vendor
- Lenovo
- Vendor
- CVE Published:
- 11 October 2024
Summary
A significant information disclosure vulnerability was identified in Lenovo's Dolby Vision Provisioning software versions before 2.0.0.2. This flaw enables a local attacker to read sensitive files on the system during the installation process of the software, potentially leading to unauthorized access to critical data. Notably, the vulnerability does not affect previously installed versions of the product.
Affected Version(s)
Dolby Vision Provisioning software 0 < 2.0.0.2
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Alaa Kachouh for reporting this issue.