{"api_version":"1","generated_at":"2026-07-23T07:41:25+00:00","cve":"CVE-2017-3747","urls":{"html":"https://cve.report/CVE-2017-3747","api":"https://cve.report/api/cve/CVE-2017-3747.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-3747","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-3747"},"summary":{"title":"CVE-2017-3747","description":"Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys.","state":"PUBLISHED","assigner":"lenovo","published_at":"2017-06-29 15:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["NVD-CWE-noinfo","Privilege escalation"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/99286","name":"http://www.securityfocus.com/bid/99286","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Lenovo Nerve Center CVE-2017-3747 Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://support.lenovo.com/us/en/product_security/LEN-15046","name":"https://support.lenovo.com/us/en/product_security/LEN-15046","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Lenovo Nerve Center for Desktops Privilege Escalation - US","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-3747","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-3747","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Lenovo Group Ltd.","product":"Lenovo Nerve Center","version":"affected Earlier than 1.70.0426","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"3747","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lenovo","cpe5":"nerve_center","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"3747","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T14:39:41.074Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"99286","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/99286"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.lenovo.com/us/en/product_security/LEN-15046"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Lenovo Nerve Center","vendor":"Lenovo Group Ltd.","versions":[{"status":"affected","version":"Earlier than 1.70.0426"}]}],"datePublic":"2017-06-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys."}],"problemTypes":[{"descriptions":[{"description":"Privilege escalation","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-06-30T09:57:01.000Z","orgId":"da227ddf-6e25-4b41-b023-0f976dcaca4b","shortName":"lenovo"},"references":[{"name":"99286","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/99286"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.lenovo.com/us/en/product_security/LEN-15046"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@lenovo.com","DATE_PUBLIC":"2017-06-22T00:00:00","ID":"CVE-2017-3747","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Lenovo Nerve Center","version":{"version_data":[{"version_value":"Earlier than 1.70.0426"}]}}]},"vendor_name":"Lenovo Group Ltd."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Privilege escalation"}]}]},"references":{"reference_data":[{"name":"99286","refsource":"BID","url":"http://www.securityfocus.com/bid/99286"},{"name":"https://support.lenovo.com/us/en/product_security/LEN-15046","refsource":"CONFIRM","url":"https://support.lenovo.com/us/en/product_security/LEN-15046"}]}}}},"cveMetadata":{"assignerOrgId":"da227ddf-6e25-4b41-b023-0f976dcaca4b","assignerShortName":"lenovo","cveId":"CVE-2017-3747","datePublished":"2017-06-29T15:00:00.000Z","dateReserved":"2016-12-16T00:00:00.000Z","dateUpdated":"2024-09-16T22:56:01.952Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-06-29 15:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["NVD-CWE-noinfo","Privilege escalation"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:lenovo:nerve_center:-:*:*:*:*:*:*:*","matchCriteriaId":"2F8A7D1B-AF5B-43B6-B1FB-39749ADC0E9B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*","matchCriteriaId":"FBC814B4-7DEC-4EFC-ABFF-08FFD9FD16AA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"3747","Ordinal":"1","Title":"CVE-2017-3747","CVE":"CVE-2017-3747","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"3747","Ordinal":"1","NoteData":"Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys.","Type":"Description","Title":"CVE-2017-3747"},{"CveYear":"2017","CveId":"3747","Ordinal":"2","NoteData":"2017-06-29","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"3747","Ordinal":"3","NoteData":"2017-06-30","Type":"Other","Title":"Modified"}]}}}