Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46687 | A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by this issue. |
Solution
Update Dolby Vision Provisioning package to version 2.0.0.2 or later. https://support.lenovo.com/us/en/downloads/ds543424-dolby-vision-provisioning-driver-for-windows-10-64-bit-version-1709-or-later-thinkpad-ideapad-ideacentre
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-158394 |
|
Fri, 15 Nov 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lenovo dolby Vision Provisioning
|
|
| CPEs | cpe:2.3:a:lenovo:dolby_vision_provisioning:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo dolby Vision Provisioning
|
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lenovo
Lenovo dolby Vision Provisioning Software |
|
| CPEs | cpe:2.3:a:lenovo:dolby_vision_provisioning_software:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo dolby Vision Provisioning Software |
|
| Metrics |
ssvc
|
Fri, 11 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by this issue. | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-10-11T19:07:47.060Z
Reserved: 2024-05-29T14:21:27.520Z
Link: CVE-2024-5474
Updated: 2024-10-11T19:07:34.223Z
Status : Analyzed
Published: 2024-10-11T16:15:14.440
Modified: 2024-11-15T17:00:35.697
Link: CVE-2024-5474
No data.
OpenCVE Enrichment
No data.
EUVD