Description
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
Published: 2026-03-11
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

An input validation vulnerability in the DeviceSettingsSystemAddin used by Lenovo Vantage and Lenovo Baiying allows a local authenticated user to modify arbitrary registry keys with elevated privileges. The flaw stems from improper validation of user input (CWE-88) and provides the attacker the ability to alter system configuration, potentially compromising system integrity.

Affected Systems

Lenovo Vantage and Lenovo Baiying installations that include DeviceSettingsSystemAddin versions prior to 1.0.8.15 are affected, as the add‑in is automatically updated by both applications.

Risk and Exploitability

The vulnerability has a CVSS score of 6.9, indicating moderate severity. The EPSS score is less than 1%, suggesting low likelihood of widespread exploitation. It is not listed in the CISA KEV catalog. Exploitation requires local authenticated access; with the add‑in's elevated privileges the attacker can modify any registry key on the target machine.

Generated by OpenCVE AI on March 17, 2026 at 15:25 UTC.

Remediation

Vendor Solution

Update Vantage DeviceSettingsSystemAddin to version 1.0.8.15 or later. DeviceSettingsSystemAddin is automatically updated by Lenovo Vantage and Baiying.


OpenCVE Recommended Actions

  • Apply Lenovo Vantage update to DeviceSettingsSystemAddin version 1.0.8.15 or later.

Generated by OpenCVE AI on March 17, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 20 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
Title Input Validation Vulnerability Allowing Local Privilege Escalation in Lenovo DeviceSettingsSystemAddin

Thu, 12 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Mar 2026 20:45:00 +0000

Type Values Removed Values Added
Description An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
First Time appeared Lenovo
Lenovo baiying
Lenovo vantage
Weaknesses CWE-88
CPEs cpe:2.3:a:lenovo:baiying:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*
Vendors & Products Lenovo
Lenovo baiying
Lenovo vantage
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-03-12T16:18:37.213Z

Reserved: 2026-01-30T19:00:44.486Z

Link: CVE-2026-1715

cve-icon Vulnrichment

Updated: 2026-03-12T15:35:50.342Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-11T21:16:14.807

Modified: 2026-03-25T18:23:21.663

Link: CVE-2026-1715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-20T15:37:12Z

Weaknesses