CVE-2023-4632: High severity lenovo system update vulnerability
Published Nov 8, 2023
·Updated
An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.
Affected Software
1 affected component
Lenovo System Update<5.08.02.25
Remediation
Information
Update Lenovo System Update to version 5.08.02.25 or later as indicated in the advisory. https://support.lenovo.com/us/en/product_security/LEN-135367
Patch Available
Event History
Nov 8, 2023
CVE Published
via MITRE·09:58 PM
Data Sourced
via MITRE·09:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-4632?
CVE-2023-4632 is an uncontrolled search path vulnerability in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.
2
How severe is CVE-2023-4632?
CVE-2023-4632 has a severity rating of 7.8 (high).
3
Which software is affected by CVE-2023-4632?
Lenovo System Update versions up to 5.08.02.25 are affected by CVE-2023-4632.
4
How can I fix CVE-2023-4632?
To fix CVE-2023-4632, it is recommended to install the latest version of Lenovo System Update provided by the vendor.
5
Where can I find more information about CVE-2023-4632?
More information about CVE-2023-4632 can be found on the Lenovo Product Security website.