Impact
The vulnerability is an improper permission assignment that allows a local authenticated user to execute arbitrary code with elevated privileges. This flaw is categorized as CWE-276 (Improper Privilege Assignment). The impact is the potential compromise of system confidentiality, integrity, and availability if an attacker can gain elevated rights.
Affected Systems
The affected product is Lenovo Dock Manager. Versions prior to 1.6.5.3 are susceptible. Updating to 1.6.5.3 or later removes the flaw.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and because the exploit is local it requires an authenticated user. EPSS data is not available and the vulnerability is not listed in CISA KEV, but the high CVSS and local nature mean that the risk remains significant until the update is applied. The official solution is to update the software.
OpenCVE Enrichment