PT-2020-20112 · Lenovo · Lenovo Vantage+1
Published
2020-10-14
·
Updated
2020-10-26
·
CVE-2020-8345
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Lenovo HardwareScan Plugin versions prior to 1.0.46.11
Description
A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature that could allow escalation of privilege.
Recommendations
For versions prior to 1.0.46.11, update to version 1.0.46.11 or later to resolve the issue.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lenovo Hardwarescanplugin
Lenovo Vantage