First published: Thu Apr 04 2019(Updated: )
A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user with local access to execute code on the system.
Credit: psirt@lenovo.com psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Bootable Usb | <mar-2019 | |
Lenovo Ideacentre | ||
Lenovo Thinkcentre | ||
Lenovo ThinkPad | ||
Lenovo Thinkstation | ||
All of | ||
Lenovo Bootable Usb | <mar-2019 | |
Any of | ||
Lenovo Ideacentre | ||
Lenovo Thinkcentre | ||
Lenovo ThinkPad | ||
Lenovo Thinkstation |
Update to Lenovo Bootable Generator version Mar-2019 (or newer).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6154 is a DLL search path vulnerability in Lenovo Bootable Generator that could allow a malicious user with local access to execute code on the system.
A malicious user with local access can exploit CVE-2019-6154 by placing a malicious DLL file in a specific search path that is used by the Lenovo Bootable Generator.
CVE-2019-6154 affects Lenovo Bootable Generator versions prior to Mar-2019.
CVE-2019-6154 has a severity rating of 7.8 (high).
To fix CVE-2019-6154, update Lenovo Bootable Generator to version Mar-2019 or later.