Impact
A vulnerability in Lenovo’s App Store and Legion Zone for Windows arises from insecure permissions enforcement when the applications are installed on a non‑system partition. This flaw permits a local user to execute arbitrary code within the context of that user. The capability to run arbitrary code risks compromising system and availability through malicious actions performed by the user.
Affected Systems
Lenovo App Store on Windows, versions earlier than 9.0.29, and Lenovo Legion Zone on Windows, earlier than 2.0.26, were distributed exclusively in the Chinese market. The issue applies when either application is installed on a non‑system partition, exposing directories to write access that can be abused by the local user.
Risk and Exploitability
The CVSS score of 7.3 signals high severity, while an EPSS score of less than 1% indicates a very low likelihood of observed exploitation. The vulnerability is not listed in the CISA KEV catalog. Attacks require local access to a machine with the affected applications, and the insecure permissions must allow the user to create or modify files used by the application. Based on the description, it is inferred that the flaw lets a local user write to application user’s privileges.
OpenCVE Enrichment