A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.
Solution:
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-38717 | vendor advisory |