Lenovo Preload Directory Vulnerability

Lenovo Preload Directory Vulnerability

Lenovo Preload Directory Vulnerability

Lenovo Security Advisory: LEN-127385

Potential Impact: Privilege Escalation

Severity: High

Scope of Impact: Lenovo-specific

CVE Identifier: CVE-2023-4706

 

Summary Description:

A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.

Due to a potential conflict between Microsoft Out of Box Experience (OOBE) and Microsoft Autopilot, the Lenovo preloaded OOBE RunOnce registry keys are suppressed, preventing the removal of the "C:\Windows\1Lenovo" directory containing the OOBE scripts. 

 

Mitigation Strategy for Customers (what you should do to protect yourself):

If affected by this vulnerability, Lenovo recommends deleting the following RunOnce registry keys and the directory containing OOBE scripts:

 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Unattend0000000020{BE2A706E-7924-4DA2-AD2A-E4F9AEFCBC62}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Unattend0000000089{492519C1-9AD9-4681-8B35-60034A80F877}

C:\Windows\1Lenovo

 

Acknowledgement:

Lenovo thanks Steven Pritchard for reporting this issue. 

 

References:

https://learn.microsoft.com/en-us/troubleshoot/windows-client/shell-experience/standard-user-cannot-run-commnad-via-runonce

 

Revision History:

Revision Date Description
2 2023-11-06 Update "Acknowledgement"
1 2023-10-10 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.

 

 

 


Alias Id:LEN-127385
Document ID:PS500579
Original Publish Date:10/10/2023
Last Modified Date:11/06/2023