First published: Wed Nov 08 2023(Updated: )
An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo System Update | <5.08.02.25 |
Update Lenovo System Update to version 5.08.02.25 or later as indicated in the advisory. https://support.lenovo.com/us/en/product_security/LEN-135367
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4632 is an uncontrolled search path vulnerability in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.
CVE-2023-4632 has a severity rating of 7.8 (high).
Lenovo System Update versions up to 5.08.02.25 are affected by CVE-2023-4632.
To fix CVE-2023-4632, it is recommended to install the latest version of Lenovo System Update provided by the vendor.
More information about CVE-2023-4632 can be found on the Lenovo Product Security website.