PT-2022-2080 · Lenovo · Lenovo Thin Installer

Published

2022-03-08

·

Updated

2022-05-04

·

CVE-2022-0636

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Lenovo Thin Installer versions prior to 1.3.0039
Description The issue is related to insufficient protection of internal data in the Lenovo Thin Installer application, which is used for optimizing update procedures. This can lead to a denial of service, where an attacker could potentially cause a system crash by exploiting the vulnerability.
Recommendations For versions prior to 1.3.0039, update to version 1.3.0039 or later to resolve the issue.

Fix

Information Disclosure

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01907
CVE-2022-0636

Affected Products

Lenovo Thin Installer