PT-2022-2221 · Lenovo · Lenovo System Update

Published

2022-04-12

·

Updated

2023-08-08

·

CVE-2022-0354

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lenovo System Update versions prior to 2022-02-25
Description The issue is related to the possibility of interactive system access during the installation of a System Update package, which displays a command prompt window. This could allow an attacker to execute arbitrary code with elevated privileges.
Recommendations For versions prior to 2022-02-25, consider restricting interactive system access during the installation of System Update packages to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2022-02304
CVE-2022-0354

Affected Products

Lenovo System Update