CVE-2024-4696: OS Command Injection
A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a specially crafted link is visited.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lenovo Service Bridgeto a version that resolves this vulnerability.Fixed in 5.0.2.17
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4696?
CVE-2024-4696 is classified as a privilege escalation vulnerability.
How do I fix CVE-2024-4696?
To fix CVE-2024-4696, upgrade Lenovo Service Bridge to version 5.0.2.17 or later.
What causes CVE-2024-4696?
CVE-2024-4696 is caused by the execution of operating system commands through specially crafted links.
Which versions of Lenovo Service Bridge are affected by CVE-2024-4696?
Lenovo Service Bridge versions prior to 5.0.2.17 are affected by CVE-2024-4696.
What type of exploitation is possible with CVE-2024-4696?
CVE-2024-4696 allows for privilege escalation through executing operating system commands.