An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Lenovo Vantage
cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*
|
— |
1.0.8.15
|
|
Lenovo Baiying
cpe:2.3:a:lenovo:baiying:*:*:*:*:*:*:*:*
|
0
|
1.0.8.15
|