CVE-2019-6154: High severity Lenovo Bootable Usb Windows vulnerability
Published Apr 10, 2019
·Updated
A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user with local access to execute code on the system.
Affected Software
10 affected components
All of the following
Lenovo Bootable Usb Windows<mar-2019
Any of the following
Lenovo Ideacentre
Lenovo Thinkcentre
Lenovo ThinkPad
Lenovo Thinkstation
Lenovo Bootable Usb Windows<mar-2019
Lenovo Ideacentre
Lenovo Thinkcentre
Lenovo ThinkPad
Lenovo Thinkstation
Remediation
Patch Available
Information
Update to Lenovo Bootable Generator version Mar-2019 (or newer).
Event History
Apr 10, 2019
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-6154?
CVE-2019-6154 is a DLL search path vulnerability in Lenovo Bootable Generator that could allow a malicious user with local access to execute code on the system.
2
How can a malicious user exploit CVE-2019-6154?
A malicious user with local access can exploit CVE-2019-6154 by placing a malicious DLL file in a specific search path that is used by the Lenovo Bootable Generator.
3
What software versions are affected by CVE-2019-6154?
CVE-2019-6154 affects Lenovo Bootable Generator versions prior to Mar-2019.
4
What is the severity of CVE-2019-6154?
CVE-2019-6154 has a severity rating of 7.8 (high).
5
How can I fix CVE-2019-6154?
To fix CVE-2019-6154, update Lenovo Bootable Generator to version Mar-2019 or later.