Information Disclosure Vulnerability in Lenovo's Dolby Vision Provisioning Software
CVE-2024-5474

5.5MEDIUM

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
11 October 2024

Summary

A significant information disclosure vulnerability was identified in Lenovo's Dolby Vision Provisioning software versions before 2.0.0.2. This flaw enables a local attacker to read sensitive files on the system during the installation process of the software, potentially leading to unauthorized access to critical data. Notably, the vulnerability does not affect previously installed versions of the product.

Affected Version(s)

Dolby Vision Provisioning software 0 < 2.0.0.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Alaa Kachouh for reporting this issue.
.