Impact
The Lenovo App Store Windows Application contains a path traversal flaw (CWE-22) that may allow a locally authenticated user to execute arbitrary code with the privileges of that user. The vulnerability arises when the application processes file paths that can be manipulated to reference directories outside the intended working directory, potentially invoking code from malicious locations.
Affected Systems
The vulnerability affects the Lenovo App Store for Windows, distributed exclusively in the Chinese market. Versions prior to 9.0.2930.0514 are susceptible. The impacted product is the Lenovo App Store Windows Application.
Risk and Exploitability
The CVSS score of 7 indicates medium to high severity, but the EPSS score of <1% (0.00132) indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV, and no public exploits have been documented. The attack vector is local and requires an authenticated user to run the Lenovo App Store; execution is limited to the user’s own privileges.
OpenCVE Enrichment