CVE-2023-3112: High severity elliptic labs ai virtual presence sensor vulnerability
Published Oct 24, 2023
·Updated
A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges.
Affected Software
3 affected components
Ellipticlabs Ai Virtual Presence Sensor<3.1.50719.1
Ellipticlabs Virtual Lock Sensor<3.1.50719.1
Lenovo Thinkpad T14 Gen 3
Remediation
Information
Upgrade to the Elliptic Virtual Lock Sensor version (or newer) indicated for your model in the advisory https://support.lenovo.com/us/en/product_security/LEN-128081
Event History
Oct 24, 2023
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-3112.
2
What is the severity of CVE-2023-3112?
The severity of CVE-2023-3112 is high with a severity value of 7.8.
3
Which software is affected by CVE-2023-3112?
The Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 and Ellipticlabs Ai Virtual Presence Sensor versions up to 3.1.50719.1 are affected by CVE-2023-3112.
4
How can an attacker exploit CVE-2023-3112?
An attacker with local access can exploit CVE-2023-3112 to execute code with elevated privileges.
5
Is Lenovo ThinkPad T14 Gen 3 affected by CVE-2023-3112?
No, Lenovo ThinkPad T14 Gen 3 is not affected by CVE-2023-3112.