A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation if an attacker already has administrative privileges.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-15740 A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation if an attacker already has administrative privileges.
Fixes

Solution

To mitigate these vulnerabilities, Lenovo recommends installing Lenovo software updates through Lenovo Vantage, Lenovo System Update, or Windows Update. Updates delivered through Update Retriever, Thin Installer, and System Update are also not affected. Lenovo installation packages version 1.2.9.3 or later are not affected.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-16T17:54:54.225Z

Reserved: 2019-01-11T00:00:00

Link: CVE-2019-6173

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-09T20:15:11.710

Modified: 2024-11-21T04:46:06.110

Link: CVE-2019-6173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.