Impact
A vulnerability in Lenovo Diagnostics and the HardwareScanAddin used by Lenovo Vantage permits a local authenticated user to perform an arbitrary file write with elevated privileges during installation or hardware scan operations. This flaw enables modification of system files, potentially replacing binaries, altering configuration files, or injecting malicious code, thereby allowing the attacker to elevate privileges. The weakness is an instance of improper path validation, as classified by CWE‑59.
Affected Systems
The affected products are Lenovo Diagnostics and Lenovo Vantage, including the HardwareScanAddin component. Versions prior to Diagnostics 5.26.0 and to Vantage and Commercial Vantage HardwareScanAddin 4.7.1.4 are susceptible. All newer builds that incorporate the listed updates are not vulnerable.
Risk and Exploitability
The CVSS base score is 6.9, indicating medium severity. No EPSS score is available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. It requires a local authenticated user with installation or scanning privileges, so the attack vector is inferred to be local. Given the potential for privilege escalation, the overall risk remains moderate to high depending on the environment.
OpenCVE Enrichment