1 results (0.001 seconds)

CVSS: 9.3EPSS: 0%CPEs: 1EXPL: 0

UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi.lenovomm.com. UpdateAgent en Lenovo Accelerator Application permite a atacantes man-in-the-middle ejecutar código arbitrario suplantando una respuesta de actualización de susapi.lenovomm.com. • https://duo.com/blog/out-of-box-exploitation-a-security-analysis-of-oem-updaters https://support.lenovo.com/us/en/product_security/len_6718 • CWE-20: Improper Input Validation •