A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed.
Solution:
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-30401 | vendor advisory |