{"api_version":"1","generated_at":"2026-07-23T11:12:09+00:00","cve":"CVE-2019-6196","urls":{"html":"https://cve.report/CVE-2019-6196","api":"https://cve.report/api/cve/CVE-2019-6196.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-6196","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-6196"},"summary":{"title":"CVE-2019-6196","description":"A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.","state":"PUBLIC","assigner":"psirt@lenovo.com","published_at":"2020-06-09 20:15:00","updated_at":"2020-06-22 15:12:00"},"problem_types":["CWE-426"],"metrics":[],"references":[{"url":"https://support.lenovo.com/us/en/product_security/len-27431","name":"https://support.lenovo.com/us/en/product_security/len-27431","refsource":"MISC","tags":["Patch","Vendor Advisory"],"title":"DLL Search Path and Symbolic Link Vulnerabilities  - US","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-6196","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-6196","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Lenovo thanks Eran Shimony at CyberArk Labs for reporting this issue","lang":""}],"nvd_cpes":[{"cve_year":"2019","cve_id":"6196","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lenovo","cpe5":"installation_package","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6196","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lenovo","cpe5":"installation_package","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@lenovo.com","DATE_PUBLIC":"2020-06-09T18:00:00.000Z","ID":"CVE-2019-6196","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Installation Packages","version":{"version_data":[{"version_affected":"<","version_value":"1.2.9.3"}]}}]},"vendor_name":"Lenovo"}]}},"credit":[{"lang":"eng","value":"Lenovo thanks Eran Shimony at CyberArk Labs for reporting this issue"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-426 Untrusted Search Path"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://support.lenovo.com/us/en/product_security/len-27431","name":"https://support.lenovo.com/us/en/product_security/len-27431"}]},"solution":[{"lang":"eng","value":"To mitigate these vulnerabilities, Lenovo recommends installing Lenovo software updates through Lenovo Vantage, Lenovo System Update, or Windows Update. Updates delivered through Update Retriever, Thin Installer, and System Update are also not affected.  Lenovo installation packages version 1.2.9.3 or later are not affected. "}],"source":{"advisory":"LEN-27431","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2020-06-09 20:15:00","lastModifiedDate":"2020-06-22 15:12:00","problem_types":["CWE-426"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH"},"exploitabilityScore":1.3,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":6.9},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:lenovo:installation_package:*:*:*:*:*:*:*:*","versionEndExcluding":"1.2.9.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"6196","Ordinal":"143867","Title":"CVE-2019-6196","CVE":"CVE-2019-6196","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"6196","Ordinal":"1","NoteData":"A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"6196","Ordinal":"2","NoteData":"2020-06-09","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"6196","Ordinal":"3","NoteData":"2020-06-09","Type":"Other","Title":"Modified"}]}}}