First published: Wed Nov 08 2023(Updated: )
A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Preload Directory |
Refer to Mitigation strategy section in the advisory: https://support.lenovo.com/us/en/product_security/LEN-127385
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-4706.
The severity of CVE-2023-4706 is high with a severity value of 7.3.
The affected software is Lenovo Preload Directory.
The CWE of CVE-2023-4706 is CWE-276.
To fix CVE-2023-4706, follow the recommendations provided by Lenovo at the following reference link: [https://support.lenovo.com/us/en/product_security/LEN-127385]