Impact
An improper link following flaw allows a local authenticated user to execute code with elevated privileges in Lenovo Vantage and Lenovo Commercial Vantage. The vulnerability enables the attacker to take advantage of a link‑following mechanism that fails to verify the destination, thereby lifting the user’s privileges to those of the executing process. Over‑exploiting this weakness could compromise system confidentiality, integrity, and availability by granting the attacker full control over the affected device.
Affected Systems
The affected products are Lenovo Vantage and Lenovo Commercial Vantage. Vulnerable versions lack the patch that fixes the link following logic. The vendors have identified the flaw and released version 10.2606.12 for Vantage and 20.2026.20.0 for Commercial Vantage as secure releases.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity for privilege escalation. No EPSS data is available, but the absence of a KEV listing suggests exploitation is not yet widespread. The attack requires local authentication, so scanners and remote exploits are not viable; however, any user with routine administrative access could trigger the flaw by interacting with a malicious link.
OpenCVE Enrichment