PT-2023-13516 · Lenovo · Lenovo Vantage Systemupdate Plugin

Published

2023-10-27

·

Updated

2023-11-07

·

CVE-2022-3700

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lenovo Vantage SystemUpdate Plugin versions 2.0.0.212 and earlier
Description A Time of Check Time of Use (TOCTOU) issue was reported that could allow a local attacker to delete arbitrary files. This issue could potentially be exploited by a local attacker.
Recommendations For versions 2.0.0.212 and earlier, update to a version later than 2.0.0.212 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2022-3700

Affected Products

Lenovo Vantage Systemupdate Plugin