A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation.
Solution:
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-103544 | vendor advisory |