Lucene search

K
lenovoLenovoLENOVO:PS500225-LENOVO-BOOTABLE-GENERATOR-VULNERABILITY-NOSID
HistoryApr 01, 2019 - 8:18 p.m.

Lenovo Bootable Generator Vulnerability - Lenovo Support US

2019-04-0120:18:41
support.lenovo.com
24

EPSS

0.001

Percentile

30.3%

Lenovo Security Advisory: LEN-25401

Potential Impact: Code execution

Severity: Medium

Scope of Impact: Lenovo-specific

CVE Identifier: CVE-2019-6154

Summary Description:

A DLL search path vulnerability was reported in Lenovo Bootable Generator that could allow a malicious user with local access to execute code on the system.

Mitigation Strategy for Customers (what you should do to protect yourself):

Update to Lenovo Bootable Generator v. Mar-2019 (or newer) for the following supported systems:

  • All Thinkpad
  • All ThinkCentre
  • All ThinkStation
  • All IdeaCentre

Acknowledgements:

Lenovo thanks SaifAllah benMassaoud & Oussama Sahnoun and Mustapha Mhenaoui for reporting this issue.

Revision History:

Revision Date Description
1 2018-04-04 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an β€œas is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.

EPSS

0.001

Percentile

30.3%

Related for LENOVO:PS500225-LENOVO-BOOTABLE-GENERATOR-VULNERABILITY-NOSID