CVE Vulnerabilities

CVE-2024-12673

Execution with Unnecessary Privileges

Published: Feb 12, 2025 | Modified: Feb 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system.

This vulnerability only affects Vantage installed on these devices:

  • Lenovo V Series (Gen 5)
  • ThinkBook 14 (Gen 6, 7)
  • ThinkBook 16 (Gen 6, 7)
  • ThinkPad E Series (Gen 1)

Weakness

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Potential Mitigations

References