A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2019-15763 | A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation. |
Fixes
Solution
To mitigate these vulnerabilities, Lenovo recommends installing Lenovo software updates through Lenovo Vantage, Lenovo System Update, or Windows Update. Updates delivered through Update Retriever, Thin Installer, and System Update are also not affected. Lenovo installation packages version 1.2.9.3 or later are not affected.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://support.lenovo.com/us/en/product_security/len-27431 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-17T00:25:55.970Z
Reserved: 2019-01-11T00:00:00
Link: CVE-2019-6196

No data.

Status : Modified
Published: 2020-06-09T20:15:11.787
Modified: 2024-11-21T04:46:09.287
Link: CVE-2019-6196

No data.

No data.