Impact
A local authenticated user may run arbitrary code with higher privileges via the Lenovo App Store. The weakness, identified as CWE-250, allows an attacker to exploit the application to elevate privileges and potentially gain full control of the affected system. This impact allows any user who can log into the local machine with App Store access to bypass security boundaries and execute malicious instructions.
Affected Systems
Lenovo App Store for Windows, distributed exclusively in the Chinese market. The vulnerability applies to all versions prior to 9.0.2930.0514; the exact version list is not enumerated in the data but the fix is provided for version 9.0.2930.0514 or newer.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity. The EPSS score is reported as <1%, suggesting that exploitation is currently rare but not impossible. The vulnerability is not listed in the CISA KEV catalog, yet it remains significant due to the local execution requirement and the ability to achieve arbitrary code execution with elevated rights. An attacker would need local authentication to the target machine and then run the Lenovo App Store to trigger the flaw.
OpenCVE Enrichment