Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges.
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/solutions/LEN-11588 | vendor advisory |
http://www.securityfocus.com/bid/95842 | vdb entry |