PT-2021-5593 · Lenovo · Lenovo System Interface Foundation

Published

2021-10-29

·

Updated

2022-05-26

·

CVE-2021-3969

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lenovo System Interface Foundation versions prior to 1.1.20.3
Description The issue is caused by a Time of Check Time of Use (TOCTOU) situation, also described as a "ситуация гонки" or race condition, in the IMController component. This could allow a local attacker to elevate their privileges.
Recommendations For versions prior to 1.1.20.3, update to version 1.1.20.3 or later to resolve the issue.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00027
CVE-2021-3969

Affected Products

Lenovo System Interface Foundation