PT-2021-5605 · Lenovo · Lenovo System Interface Foundation

Published

2021-10-29

·

Updated

2022-05-26

·

CVE-2021-3922

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lenovo System Interface Foundation versions prior to 1.1.20.3
Description A race condition issue in the IMController component of Lenovo System Interface Foundation allows a local attacker to potentially elevate their privileges by connecting and interacting with the IMController child process' named pipe.
Recommendations For versions prior to 1.1.20.3, update to version 1.1.20.3 or later to resolve the issue.

Fix

Time Of Check To Time Of Use

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00027
BDU:2022-00039
CVE-2021-3922

Affected Products

Lenovo System Interface Foundation