Lenovo System Update Vulnerability

Lenovo System Update Vulnerability

Lenovo System Update Vulnerability

Lenovo Security Advisory: LEN-135367

Potential Impact: Privilege Escalation

Severity: High

Scope of Impact: Lenovo-specific

CVE Identifier: CVE-2023-4632

 

Summary Description:

An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.

 

Mitigation Strategy for Customers (what you should do to protect yourself):

Update Lenovo System Update to version 5.08.02.25 or later.

 

Acknowledgement:

Lenovo thanks Matt Nelson, Hunter Orrantia and Max Harley of SpecterOps for reporting this issue. 

 

References:

https://support.lenovo.com/us/en/solutions/ht003029

 

Revision History:

Revision Date Description
1 2023-10-10 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.

 


Alias Id:LEN-135367
Document ID:PS500581
Original Publish Date:10/10/2023
Last Modified Date:10/10/2023