QID 377596
Date Published: 2022-09-21
QID 377596: Lenovo IMController Local Privilege Escalation Vulnerability (LEN-75210)
ImController.exe file is a software component of Lenovo System Interface Foundation by Lenovo.
The ImController service comes installed on certain Lenovo devices, for example NCC found the service installed on a ThinkPad workstation. The service runs as the SYSTEM user and periodically executes child processes which perform system configuration and maintenance tasks.
Affected Products:
Lenovo ImController prior to version 1.1.20.3
QID Detection Logic
:
This QID checks Vulnerable versions of ImController installed on windows system.
An attacker can elevate their privileges to that of the SYSTEM user from a user that is able to write files to the filesystem.
Solution
Customers are recommended to refer LEN-75210 for updates.
Vendor References
CVEs related to QID 377596
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| LEN-75210 |
|