Impact
The Lenovo FileZ a local authenticated user to elevate privileges. This vulnerability allows an attacker to gain higher rights within the local environment, threatening confidentiality, integrity, and availability. The weakness is classified as CWE-276.
Affected Systems
Lenovo FileZ Client and Lenovo FileZ Enterprise are affected. No specific version constraints are provided; therefore, any release may be vulnerable until the vendor releases an update. Administrators should verify the installed versions against the vendor's recommended updates.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability. The EPSS score is not available, leaving the likelihood of real-world exploitation uncertain. The flaw is not listed in the CISA KEV catalog. Local authenticated users can exploit it without additional conditions; the attack path is straightforward, requiring only local access.
OpenCVE Enrichment