First published: Mon Jun 05 2023(Updated: )
A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Thinkpad Hybrid Usb-c With Usb-a Dock Firmware | <1.0.35_v2 | |
Lenovo Thinkpad Hybrid Usb-c With Usb-a Dock Firmware |
Customers should update their ThinkPad Dock Firmware Update Tool to version v1.0.35_v2 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this local privilege escalation vulnerability is CVE-2022-4569.
The title for this vulnerability is 'A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool'.
The severity of CVE-2022-4569 is high with a severity value of 7.8.
The Lenovo ThinkPad Hybrid USB-C with USB-A Dock Firmware version up to 1.0.35_v2 on Windows is affected by CVE-2022-4569.
An attacker with local access can exploit CVE-2022-4569 to execute code with elevated privileges during the package upgrade or installation.