Impact
An improperly protected key exists in Lenovo Dock Manager that lets a local authenticated user gain higher privileges than intended. The flaw is a credential management weakness that could give the user unauthorized control over system functions, potentially modifying or executing code with elevated rights. The vulnerability does not extend privileges beyond the local machine and does not provide remote attack vectors.
Affected Systems
Lenovo Dock Manager, any version before 1.6.5.3. The vendor specifies that updating to 1.6.5.3 or later removes the exposed key and resolves the privilege‑escalation risk.
Risk and Exploitability
The CVSS score of 7 indicates high severity. EPSS data is not available, so exploitation likelihood is unknown, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires a local authenticated user who can run Dock Manager; no network or external access is needed. Because the flaw involves a protected key, an attacker with local presence could extract or use the key to elevate privileges, but no obvious remote exploit exists.
OpenCVE Enrichment