Description
During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.
Published: 2026-08-13
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improperly protected key exists in Lenovo Dock Manager that lets a local authenticated user gain higher privileges than intended. The flaw is a credential management weakness that could give the user unauthorized control over system functions, potentially modifying or executing code with elevated rights. The vulnerability does not extend privileges beyond the local machine and does not provide remote attack vectors.

Affected Systems

Lenovo Dock Manager, any version before 1.6.5.3. The vendor specifies that updating to 1.6.5.3 or later removes the exposed key and resolves the privilege‑escalation risk.

Risk and Exploitability

The CVSS score of 7 indicates high severity. EPSS data is not available, so exploitation likelihood is unknown, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires a local authenticated user who can run Dock Manager; no network or external access is needed. Because the flaw involves a protected key, an attacker with local presence could extract or use the key to elevate privileges, but no obvious remote exploit exists.

Generated by OpenCVE AI on August 13, 2026 at 17:09 UTC.

Remediation

Vendor Solution

Update Lenovo Dock Manager to version 1.6.5.3 or later.


OpenCVE Recommended Actions

  • Apply the Lenovo update that brings Dock Manager to version 1.6.5.3 or later to remove the exposed key.
  • Restrict local accounts that can run Dock Manager, ensuring only required users and processes have access.
  • Audit and monitor for privilege‑escalation indicators, and enforce least‑privilege principles on systems running Dock Manager.

Generated by OpenCVE AI on August 13, 2026 at 17:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Improperly Protected Key Enables Local Privilege Escalation in Lenovo Dock Manager

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.
First Time appeared Lenovo
Lenovo dock Manager
Weaknesses CWE-261
CPEs cpe:2.3:a:lenovo:dock_manager:*:*:*:*:*:*:*:*
Vendors & Products Lenovo
Lenovo dock Manager
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo Dock Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-08-13T15:55:32.534Z

Reserved: 2026-07-16T19:22:22.180Z

Link: CVE-2026-63424

cve-icon Vulnrichment

Updated: 2026-08-13T15:55:28.268Z

cve-icon NVD

Status : Received

Published: 2026-08-13T15:19:55.223

Modified: 2026-08-13T16:18:32.217

Link: CVE-2026-63424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T17:45:03Z

Weaknesses
  • CWE-261

    Weak Encoding for Password