Impact
A command injection flaw exists in the Lenovo Tianxi AI Agent PC Application that enables a local user to execute arbitrary operating system commands by opening a specially crafted link CWE‑78 and can lead to complete compromise of the affected system, exposing all data and processes to the attacker.
Affected Systems
All installations of the Lenovo Tianxi AI Agent PC Application distributed in the Chinese market, regardless of version, are potentially vulnerable until updated. The vendor’s advisory lists version 4.2.1.8111 or later as containing the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4, indicating high severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog, but the lack of exploitation evidence does not reduce the risk of local exploitation. Attacks require a local user to open a malicious link within the application, meaning any user with access to the system could trigger the flaw control.
OpenCVE Enrichment