Lenovo Accessories and Display Manager (LADM) and Lenovo Display Control Center (LDCC) Vulnerabilities

Lenovo Accessories and Display Manager (LADM) and Lenovo Display Control Center (LDCC) Vulnerabilities

Lenovo Accessories and Display Manager (LADM) and Lenovo Display Control Center (LDCC) Vulnerabilities

Lenovo Security Advisory: LEN-174319

Potential Impact: Privilege Escalation

Severity: High

Scope of Impact: Lenovo-specific

CVE Identifier: CVE-2024-4762, CVE-2024-6001

 

Summary Description:

An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges. CVE-2024-4762

An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges. CVE-2024-6001

 

Mitigation Strategy for Customers (what you should do to protect yourself):

Update LADM to version 1.0.5.05 or later to address CVE-2024-4762 and CVE-2024-6001.

Update LDCC to version 3.0.32161.0 or later to address CVE-2024-4762.

 

 

Lenovo also offers tools to assist with update management as an alternative to the manual steps described above. Refer to the following for additional help:

PC Products and Software: https://support.lenovo.com/us/en/solutions/ht504759

Server and Enterprise Software: https://support.lenovo.com/us/en/solutions/lnvo-lxcaupd and https://datacentersupport.lenovo.com/us/en/documents/lnvo-center

 

Acknowledgement:

Lenovo thanks Alain Rodel of Neodyme AG for reporting CVE-2024-4762.

Lenovo thanks jh_535252 for reporting CVE-2024-6001.

 

Revision History:

Revision Date Description
1 2024-12-10 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.


Alias Id:LEN-174319
Document ID:PS500677
Original Publish Date:12/09/2024
Last Modified Date:12/19/2024