QID 376718
Date Published: 2022-07-07
QID 376718: Lenovo System Update Privilege Escalation Vulnerability (len-76673)
A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update package released before 2022-02-25 that displays a command prompt window.
Affected Products:
Update package released before 2022-02-25
QID Detection Logic
:
This QID checks for update package release date before 2022-02-25
Successful exploitation could allow a local user with interactive system access the ability to execute code with elevated privileges
Solution
Customers are recommended to update firmware. Refer to LEN-76673 for firmware updates.
Vendor References
CVEs related to QID 376718
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| LEN-76673 |
|