A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.
Solution:
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://iknow.lenovo.com.cn/detail/dc_198418.html | exploit vendor advisory |