Impact
An improper link following flaw in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage allows a local authenticated user to delete arbitrary files with elevated privileges. The vulnerability stems from insufficient validation of URLs, which can be exploited to trigger file system operations beyond the intended scope. Consequences include accidental or intentional loss of critical data, possible service disruption, and potential compromise of system integrity in environments where data preservation is essential. The weakness is reflected by CWE‑59.
Affected Systems
Affected per CNA are Lenovo Vantage and Lenovo Commercial Vantage through the VantageCoreAddin component. The fix applies to any installation of the addin that is not yet updated to version 1.1.0.51 or later. No specific version shambles are disclosed, so any pre‑1.1.0.51 build is considered vulnerable. Users should verify their addin version and upgrade accordingly.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, yet the ability to act with elevated privileges elevates the risk in controlled environments. EPSS data is not available, and the vulnerability is not yet listed in CISA’s KEV catalog, implying no known public exploits yet. An attacker must first authenticate locally, but once authenticated, the flaw permits direct file deletion, making it a valuable vector for destructive or destructive attacks.
OpenCVE Enrichment