CVE-2019-6149: High severity Lenovo Dynamic Power Reduction vulnerability
An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-6149?
CVE-2019-6149 is an unquoted search path vulnerability identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0.
What is the severity of CVE-2019-6149?
CVE-2019-6149 has a severity value of 6.7, which is considered high.
How does CVE-2019-6149 affect Lenovo Dynamic Power Reduction Utility?
CVE-2019-6149 could allow a malicious user with local access to execute code with administrative privileges in Lenovo Dynamic Power Reduction Utility versions prior to 2.2.2.0.
Is Lenovo ThinkPad X1 Carbon affected by CVE-2019-6149?
No, Lenovo ThinkPad X1 Carbon is not affected by CVE-2019-6149.
How can I fix CVE-2019-6149?
Update Lenovo Dynamic Power Reduction Utility to version 2.2.2.0 or later to fix the CVE-2019-6149 vulnerability.