Lucene search

K
lenovoLenovoLENOVO:PS500285-NOSID
HistoryNov 09, 2019 - 1:19 p.m.

Lenovo System Interface Foundation Vulnerabilities - US

2019-11-0913:19:48
support.lenovo.com
15

0.001 Low

EPSS

Percentile

43.1%

Lenovo Security Advisory: LEN-29198

Potential Impact: Lateral Arbitrary Code Execution

Severity: Medium

Scope of Impact: Lenovo-specific

CVE Identifier: CVE-2019-6186, CVE-2019-6189

Summary Description:

Potential vulnerabilities were reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to execute code as another user (CVE-2019-6186) or allow an administrative user to load an unsigned DLL (CVE-2019-6189).​

Mitigation Strategy for Customers (what you should do to protect yourself):

Update Lenovo System Interface Foundation to version 1.1.18.3 (or higher): https://support.lenovo.com/downloads/ds105970

Acknowledgement:

CVE-2019-6186: Lenovo thanks Zhiniang Peng of Qihoo 360 Core security & Jiadong Lu of South China University of Technology for reporting this issue.

CVE-2019-6189: Lenovo thanks Peleg Hadar of SafeBreach Labs for reporting this issue.

Revision History:

Revision Date Description
1 2019-11-19 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an β€œas is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.

0.001 Low

EPSS

Percentile

43.1%

Related for LENOVO:PS500285-NOSID