Page 13 of 66 results (0.009 seconds)

CVSS: 7.8EPSS: 0%CPEs: 151EXPL: 0

A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path. Se identificó una vulnerabilidad de escalado de privilegios en Lenovo Active Protection System para versiones de sistemas ThinkPad anteriores a la 1.82.0.17. Un atacante con privilegios locales podría ejecutar código con privilegios de administrador a través de una ruta de servicio sin entrecomillar. • http://www.securityfocus.com/bid/100305 https://support.lenovo.com/us/en/product_security/LEN-15765 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code with administrative privileges. Se ha identificado una vulnerabilidad de ruta de búsqueda sin entrecomillar en el driver para ThinkPad Compact USB Keyboard con versiones de TrackPoint anteriores a la 1.5.5.0. Esto podría permitir que un atacante con privilegios locales ejecutase código con privilegios administrativos. • https://support.lenovo.com/us/en/product_security/LEN-15061 • CWE-428: Unquoted Search Path or Element •

CVSS: 3.3EPSS: 0%CPEs: 3EXPL: 0

In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation. En el controlador de Lenovo Power Management anterior a versión 1.67.12.24, un usuario local puede modificar el firmware del trackpoint y evitar que el trackpoint funcione correctamente. Este problema solo afecta a la 5a generación de ThinkPad X1 Carbon. • https://support.lenovo.com/us/en/product_security/LEN-14440 •

CVSS: 4.7EPSS: 0%CPEs: 148EXPL: 0

A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be altered (such as boot sequence). The setting or changing of BIOS passwords is not affected by this vulnerability. Una vulnerabilidad ha sido identificada en un controlador de kernel firmado para la BIOS de algunos sistemas ThinkPad que pueden permitir a un atacante con privilegios nivel administrador de Windows llamar a servicios System Management Mode (SMM). Esto puede conducir a un ataque de denegación de servicio o permitir que ciertas variables o ajustes BIOS sean alterados (como una secuencia boot). • http://www.securityfocus.com/bid/94409 https://support.lenovo.com/us/en/solutions/LEN_8327 • CWE-284: Improper Access Control •

CVSS: 9.3EPSS: 0%CPEs: 1EXPL: 0

Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Lenovo Bluetooth. Vulnerabilidad de ruta de búsqueda no confiable en Lenovo Thinkpad Bluetooth con Enhanced Data Rate Software 6.4.0.2900 y anteriores permite a usuarios locales y, posiblemente, a un atacante remoto, ejecutar código arbitrario y llevar a cabo ataques de secuestro de DLL a través de un troyano DLL situado en la misma carpeta que el archivo que procesa Lenovo Bluetooth. • http://secunia.com/advisories/51846 http://technet.microsoft.com/en-us/security/msvr/msvr13-001 http://www.osvdb.org/89483 http://www.securityfocus.com/bid/57504 https://exchange.xforce.ibmcloud.com/vulnerabilities/81428 •