Impact
During an internal assessment, Lenovo Smart Connect for Windows was found to allow a local authenticated user to read or otherwise access files belonging to a different user on the same machine. The vulnerability arises from improper access control, permitting data leakage across user boundaries. This flaw corresponds to CWE‑306 and can lead to the disclosure of private information, user credentials, or confidential documents stored on a shared system.
Affected Systems
The issue affects Lenovo Smart Connect for Windows running versions prior to 09.0.2.003.000. All earlier releases are potentially vulnerable until the user applies the vendor patch that introduces correct owner checks for file access. The product is used primarily on Windows desktops and laptops, so any machine with Smart Connect installed and a local user who can create or modify files may be impacted.
Risk and Exploitability
The CVSS base score of 6.8 indicates a medium severity vulnerability. Exploitability is limited to local authenticated users, and the EPSS score of < 1% suggests a very low exploitation probability. The vulnerability is not listed in the CISA KeV catalog, implying no known widespread exploitation. Organizations with Smart Connect should treat the flaw as a data‑privacy risk and apply the patch promptly.
OpenCVE Enrichment