Impact
During an internal security assessment, Lenovo identified a flaw in its Accessories and Display Manager for Enterprise for Windows that permits a local authenticated user to run arbitrary code with elevated privileges. The weakness, classified as CWE‑321, enables an attacker with an existing user account to bypass typical privilege boundaries and execute code at the system level. This could compromise sensitive data, alter system configurations, or deploy malware, posing a serious security risk.
Affected Systems
The affected product is Lenovo Accessories and Display Manager for Enterprise for Windows on all supported Windows platforms. No specific build details are listed, but the vendor recommends applying update 1.0.9 or later, which contains the fix. All installations of the legacy version are potentially susceptible.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and because the vulnerability only requires local, authenticated access, it can be exploited by any user with standard permissions on the target system. EPSS data is not available, and the vulnerability is not currently in the CISA KEV catalog, but the high severity and lack of mitigation expose systems to significant damage if exploited. Attackers could leverage this flaw to execute arbitrary code, escalating privileges to full system control and thereby compromising confidentiality, integrity, and availability.
OpenCVE Enrichment