Lenovo Dynamic Power Reduction Utility CVE-2019-6149 Local Privilege Escalation Vulnerability
BID:107438
CVE-2019-6149 |Info
Lenovo Dynamic Power Reduction Utility CVE-2019-6149 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 107438 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-6149 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 14 2019 12:00AM |
| Updated: | Mar 14 2019 12:00AM |
| Credit: | Kenni Lund from Improsec |
| Vulnerable: |
Lenovo Dynamic Power Reduction Utility 2.1.0.4 Lenovo Dynamic Power Reduction Utility 1.0.0.26 |
| Not Vulnerable: |
Lenovo Dynamic Power Reduction Utility 2.2.2.0 |
Discussion
Lenovo Dynamic Power Reduction Utility CVE-2019-6149 Local Privilege Escalation Vulnerability
Lenovo Dynamic Power Reduction Utility is prone to a local privilege-escalation vulnerability.
Local attackers may exploit this issue to execute arbitrary code with administrative privileges.
Versions prior to Dynamic Power Reduction Utility 2.2.2.0 are vulnerable.
Lenovo Dynamic Power Reduction Utility is prone to a local privilege-escalation vulnerability.
Local attackers may exploit this issue to execute arbitrary code with administrative privileges.
Versions prior to Dynamic Power Reduction Utility 2.2.2.0 are vulnerable.
Exploit / POC
Lenovo Dynamic Power Reduction Utility CVE-2019-6149 Local Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Lenovo Dynamic Power Reduction Utility CVE-2019-6149 Local Privilege Escalation Vulnerability
References:
References:
- Lenovo Homepage (lenovo)
- Dynamic Power Reduction Utility Vulnerability (Lenovo)