A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.11 that could allow escalation of privilege.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-29212 A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.11 that could allow escalation of privilege.
Fixes

Solution

Update the Lenovo HardwareScan Plugin to version 1.0.46.11. The Lenovo HardwareScan Plugin is automatically updated by the Lenovo System Interface Foundation Service. To immediately start the update process, reboot the computer or restart the "System Interface Foundation Service" service. To verify the Lenovo HardwareScan Plugin version: Open File Explorer and navigate to C:\ProgramData\Lenovo\ImController\Plugins\LenovoHardwareScanPlugin\x64 Right click on LenovoHardwareScanPlugin.dll and select Properties. Click on the Details tab. Read the File version.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-04T09:56:28.341Z

Reserved: 2020-01-28T00:00:00

Link: CVE-2020-8345

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-14T22:15:13.577

Modified: 2024-11-21T05:38:44.940

Link: CVE-2020-8345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.