PT-2025-1583 · Lenovo · Lenovo Browser+2

Gareth Evans

+1

·

Published

2025-01-14

·

Updated

2025-01-17

·

CVE-2024-10253

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Lenovo PC Manager (affected versions not specified) Lenovo Browser (affected versions not specified) Lenovo App Store (affected versions not specified)
Description A potential TOCTOU vulnerability was reported that could allow a local attacker to cause a system crash. This issue affects Lenovo software, including PC Manager, Lenovo Browser, and Lenovo App Store.
Recommendations For PC Manager, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Lenovo Browser, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Lenovo App Store, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-10253

Affected Products

Lenovo App Store
Lenovo Browser
Lenovo Pcmanager