PT-2024-1558 · Lenovo · Lenovo Vantage

Published

2024-01-09

·

Updated

2024-01-26

·

CVE-2023-6044

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lenovo Vantage (affected versions not specified)
Description A privilege escalation issue was reported that could allow a local attacker with physical access to impersonate Lenovo Vantage Service and execute arbitrary code with elevated privileges. The vulnerability is related to authentication bypass via spoofing, which may enable an attacker to execute arbitrary code with elevated privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

BDU:2024-01103
CVE-2023-6044

Affected Products

Lenovo Vantage