Impact
A local authenticated user can bypass authentication checks in Lenovo Software Fix and execute arbitrary code with elevated privileges. The flaw is classified under CWE-290, indicating an authentication bypass that undermines proper access control.
Affected Systems
Lenovo Software Fix is impacted. The vendor recommends updating to version 7.6.2.10 or later, which contains the fix for this flaw. No other product or version details are specified in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 8.5, indicating high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring a local authenticated user to exploit the authentication bypass and gain elevated rights.
OpenCVE Enrichment