CVE-2019-6154
 
Severity Score
7.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user with local access to execute code on the system.
Se informó de una vulnerabilidad en la ruta de búsqueda de DLL en Lenovo Bootable Generator, anterior a la versión Mar-2019, que podría permitir a un usuario malicioso con acceso local ejecute código en el sistema.
*Credits:
Lenovo thanks SaifAllah benMassaoud & Oussama Sahnoun and Mustapha Mhenaoui for reporting this issue.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-01-11 CVE Reserved
- 2019-04-10 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-426: Untrusted Search Path
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.lenovo.com/solutions/LEN-25401 | 2019-10-09 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lenovo Search vendor "Lenovo" | Bootable Usb Search vendor "Lenovo" for product "Bootable Usb" | < mar-2019 Search vendor "Lenovo" for product "Bootable Usb" and version " < mar-2019" | windows |
Affected
| in | Lenovo Search vendor "Lenovo" | Ideacentre Search vendor "Lenovo" for product "Ideacentre" | - | - |
Safe
|
Lenovo Search vendor "Lenovo" | Bootable Usb Search vendor "Lenovo" for product "Bootable Usb" | < mar-2019 Search vendor "Lenovo" for product "Bootable Usb" and version " < mar-2019" | windows |
Affected
| in | Lenovo Search vendor "Lenovo" | Thinkcentre Search vendor "Lenovo" for product "Thinkcentre" | - | - |
Safe
|
Lenovo Search vendor "Lenovo" | Bootable Usb Search vendor "Lenovo" for product "Bootable Usb" | < mar-2019 Search vendor "Lenovo" for product "Bootable Usb" and version " < mar-2019" | windows |
Affected
| in | Lenovo Search vendor "Lenovo" | Thinkpad Search vendor "Lenovo" for product "Thinkpad" | - | - |
Safe
|
Lenovo Search vendor "Lenovo" | Bootable Usb Search vendor "Lenovo" for product "Bootable Usb" | < mar-2019 Search vendor "Lenovo" for product "Bootable Usb" and version " < mar-2019" | windows |
Affected
| in | Lenovo Search vendor "Lenovo" | Thinkstation Search vendor "Lenovo" for product "Thinkstation" | - | - |
Safe
|