Impact
An input validation vulnerability in the DeviceSettingsSystemAddin used by Lenovo Vantage and Lenovo Baiying allows a local authenticated user to modify arbitrary registry keys with elevated privileges. The flaw stems from improper validation of user input (CWE-88) and provides the attacker the ability to alter system configuration, potentially compromising system integrity.
Affected Systems
Lenovo Vantage and Lenovo Baiying installations that include DeviceSettingsSystemAddin versions prior to 1.0.8.15 are affected, as the add‑in is automatically updated by both applications.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating moderate severity. The EPSS score is less than 1%, suggesting low likelihood of widespread exploitation. It is not listed in the CISA KEV catalog. Exploitation requires local authenticated access; with the add‑in's elevated privileges the attacker can modify any registry key on the target machine.
OpenCVE Enrichment