Impact
A local authentication bypass flaw allows a user with access to Lenovo System Update to run arbitrary code with elevated privileges. This results in full control over the affected Windows machine, compromising confidentiality, integrity, and availability. The weakness is identified as CWE‑290.
Affected Systems
Lenovo System Update for Windows is impacted. Versions older than 5.08.04.85 are vulnerable and can be exploited by a local authenticated user.
Risk and Exploitability
The CVSS score of 7.3 marks the vulnerability as high severity. EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, yet it remains a local threat. Once the authentication check is bypassed, an attacker can achieve privilege escalation by executing arbitrary code. Applying the vendor update eliminates the risk.
OpenCVE Enrichment